The package includes tests, a changelog, a README, and a GitHub release, while its organization-backed repository is still unarchived. It has no security policy or automated security scanning, leaving maintenance transparency weaker.
57%
Total Score
75
86
50
The package has 8 releases over roughly 6 years, but no releases in the last 12 months and its latest release was about 19 months ago. This points to reduced maintenance activity rather than outright abandonment.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, reinforcing the long gap since the latest release. The repository was pushed more recently than that window, so this is a maintenance concern, not proof of abandonment.
Composer build tooling is present, but no security-scanning tools were detected. That weakens ongoing maintenance and vulnerability-detection transparency.
The linked repository has no security policy, leaving no documented route for reporting vulnerabilities or describing security handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ceus-media/common Version ^1.1 | 1.1.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.