The package has a sizable runtime dependency set, no security policy, and no recent repository activity. Its MIT declaration, matching repository, and GitHub release history provide some transparency, but the long-maintenance gap makes adoption risky.
36%
Total Score
0
50
71
67
The latest release was over 6 years ago, with no releases in the past 12 months and only 3 releases overall. This is strong evidence of abandonment risk for a package intended as a reusable framework core.
The repository recorded 0 commits and 0 active maintainers in the past 3 months, consistent with the package's long release gap. No provided signal shows current maintenance capacity.
The package declares 10 runtime dependencies, including several substantial framework, mail, database, and utility components. This increases maintenance and compatibility exposure for an otherwise inactive package.
The package contains only 9 source and configuration files, with no documentation or test files visible in the tree. This is a small project footprint and leaves limited evidence of maturity.
The release has no README, while the repository also reports no tests or changelog; missing tests and changelog are normal packaging practice, but the GitHub release capability is a modest positive for release transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.1 | — | — |
tedivm/stash Version ^0.14.2 | — | — |
nesbot/carbon Version ^2.17 | — | — |
zafranf/helpers Version dev-master | — | — |
jenssegers/agent Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.