The package is clearly licensed, recently released, and has a documented security contact. Ongoing work is concentrated entirely in one contributor, while the repository reports no security-scanning tooling or tests, limiting confidence in long-term resilience.
70%
Total Score
75
94
83
All 19 recent commits came from one contributor, so maintenance depends entirely on a single person and has limited handoff resilience.
Composer is used for builds, but no security-scanning tools were detected, leaving a meaningful verification gap for a framework with database, authentication, and application functionality.
No GitHub Actions workflows were present, so there were no workflow hazards to flag; this also means the audit provides no evidence of automated CI or security checks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 | — | — |
tracy/tracy Version ^2.12 | — | — |
opis/closure Version ^3.6 | — | — |
yuga/runtime Version ^1.0 | — | — |
symfony/finder Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.