The repository is not archived, matches the package name, and has a small, straightforward Composer dependency profile. Missing consumer documentation and security processes reduce transparency for future maintenance.
58%
Total Score
100
79
50
The artifact has no README, while tests and a changelog are normally repository concerns and are not expected in a published package. For an extension consumers integrate into a project, the missing README still reduces usability and transparency.
Only two releases have been published since September 2023, with no release in over two years; this indicates a thin and currently inactive maintenance history.
Composer is used for builds, which is appropriate, but the repository reports no security-scanning tools, leaving less evidence of ongoing supply-chain hygiene.
The repository has no security policy, so there is no documented route for reporting vulnerabilities or explaining security maintenance practices.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.0 || ^12.0 | — | — |
blueways/bw-icons Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.