The package includes a substantial README, repository tests, and frequent recent releases. Its single active contributor, absent security policy, and pre-1.0 version leave meaningful maintenance and transparency caveats.
73%
Total Score
67
100
86
75
The repository owner is a personal GitHub account rather than an organization, so the concentrated contributor activity is not visibly supported by organizational handoff capacity.
One contributor made all 183 commits in the last 3 months, leaving no demonstrated second maintainer to provide continuity if that contributor becomes unavailable.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy, so there is no documented channel or process for reporting and handling vulnerabilities.
Version 0.12.1 is not a stable major release, so its API may still change. It is not a prerelease, which partly offsets the risk for adoption.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
aimeos/pagible-core Version 0.12.* | — | — |
aimeos/pagible-graphql Version 0.12.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.