It remains a beta release, and the repository has no security policy or security-scanning tooling. The Apache-2.0 license and matching source repository provide basic transparency.
32%
Total Score
50
60
50
The package has had only two releases, with the latest published in September 2015 and none in the last 12 months. This strongly indicates abandonment risk for a dependency released as a beta.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the latest push being over nine years ago. This is strong evidence of inactive maintenance.
There were no new or closed issues or pull requests in the last month. While a zero open-issue count is not inherently negative, the lack of activity reinforces the broader abandonment concern.
Composer is used for the build, but no security-scanning tooling is present. This is a hygiene gap rather than evidence that the release is unsafe on its own.
The repository has no security policy. For an integration package that may handle service credentials or campaign data, this reduces transparency around vulnerability reporting.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
campaignchain/core Version 1.0.0-beta.2 | — | — |
campaignchain/hook-assignee Version 1.0.0-beta.2 | — | — |
campaignchain/hook-duration Version 1.0.0-beta.2 | — | — |
campaignchain/location-citrix Version 1.0.0-beta.2 | — | — |
campaignchain/operation-gotowebinar Version 1.0.0-beta.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.