The MIT license and absence of install-time scripts are reassuring. The package includes its source and a changelog, but its README still contains placeholder sections and no security policy is provided.
37%
Total Score
0
71
75
The latest release was published in February 2019, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment risk despite an initially regular release interval.
The repository recorded no commits and no active maintainers in the last three months, consistent with the last push occurring over seven years ago. The repository is not archived, but that does not compensate for the prolonged inactivity.
A README and changelog are present, and the absence of tests in the published artifact is normal packaging practice. However, the README contains multiple placeholder sections, reducing transparency for consumers.
The repository uses Composer, which supports reproducible dependency management, but no security-scanning tooling was detected. This is a maintenance and transparency gap rather than evidence of unsafe behavior by itself.
No repository security policy was found, leaving vulnerability reporting expectations unclear. This adds a modest transparency concern alongside the broader signs of inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0-RC1 | — | — |
unionco/syncdb Version ^0.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.