Documentation, licensing, and organization backing are solid, while the project shows sustained recent work. The alpha status, concentrated contribution, absent security scanning, and workflow pinning gaps warrant extra care before production adoption.
68%
Total Score
88
50
88
75
Seventeen runtime dependencies is a substantial graph for a framework, increasing upgrade and transitive-maintenance exposure, though the breadth is understandable for a full-stack framework.
Three contributors were active, but one produced about 75% of recent commits; the organization-owned project provides some handoff capacity, partially offsetting this concentration.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful supply-chain hygiene gap for a framework with 17 runtime dependencies.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
This release is a prerelease and 73% of recent releases are prereleases, so the API and behavior may still change even though the major version is established.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.18.4 | — | — |
doctrine/dbal Version ^3.10 || ^4.4 | — | — |
katanaphp/blade Version dev-integration/zubzet#ac9a8f2d338d0e6e7fd8ea5094ede615e9fb6a5c | — | — |
monolog/monolog Version ^2.11 | — | — |
symfony/console Version 7.* || 6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.