The repository contains tests, a README, and a changelog, and its workflow audit completed cleanly. The declared GPL-3.0-or-later license conflicts with Apache-2.0 detected in the artifact; confirm which terms apply before adopting.
68%
Total Score
83
81
67
The manifest declares GPL-3.0-or-later, while the artifact detector identifies Apache-2.0 license text. This mismatch creates real legal ambiguity despite the presence of license files.
The package has five releases over about five and a half years, with a median interval of about 405 days and one release in the last 12 months. The latest release is recent, but the overall cadence is slow.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the recent repository push and current release partly offset abandonment concerns.
The repository uses Composer and Make, but no security scanning tool was detected. The missing scanning is a modest transparency and hygiene gap, not evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ceus-media/common Version 1.1.* | ^1.1.x-dev | — | — |
ceus-media/hydrogen-framework Version 1.1.* | 1.1.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.