The package includes tests, release notes, a clear license, and an organization-backed repository. Its single registry maintainer and absent security policy leave less resilience and transparency than a mature dependency should have.
62%
Total Score
67
86
75
Only one account has registry publish access, reducing publishing redundancy. The organization-backed repository partly compensates for this, so the result is a moderate resilience concern rather than a severe risk.
The package has existed since 2016 with seven releases, but has had no release in the last 12 months and its latest release was in October 2024. This indicates a real maintenance slowdown, though the release history is established rather than abandoned outright.
The repository recorded zero commits and zero active maintainers in the last three months, which supports the concern that maintenance has gone quiet. No newer release or commit activity is provided to offset that signal.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected. The build setup is positive; the missing scanning coverage is a modest hygiene concern.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear. This is a transparency gap, but it is not severe enough to make the package unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ceus-media/common Version ^1.0 | 1.0.x-dev | — | — |
ceus-media/router Version ^0.5 | 0.5.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.