The repository is small but clearly matches the package, with a usable README and no install-time scripts. Its license files exist, though the manifest says GPL-2.0-only while the detected file says MIT. No security policy or scanning is present.
38%
Total Score
0
100
67
83
This package has only one release, published about 6 years and 11 months ago, with no releases in the last 12 months. That strongly suggests abandonment risk for a framework integration.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long release gap. The repository is not archived, but there is no observed recent maintenance to offset the inactivity.
The artifact includes a license file and the repository also has one, so licensing is not absent. However, the manifest declares GPL-2.0-only while the detected artifact license is MIT, creating a material licensing ambiguity.
The repository has no security policy and no documented security scanning tools were found in the collected repository tooling. This reduces transparency for a package that performs database schema and data operations.
The only release is v0.1, indicating an immature version line even though it is not marked as a prerelease. Combined with the lack of subsequent releases, this leaves compatibility confidence low.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ezsystems/ezpublish-kernel Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.