The tiny README gives consumers little integration guidance, and the repository has no security scanning. The organization-owned repository and explicit LGPL-3.0+ license provide useful transparency.
42%
Total Score
75
100
79
83
The package includes a README, but it is only 31 characters long and offers little guidance for consumers. The absence of tests and a changelog is normal for a published artifact and is not treated as a gap.
The latest release was published in May 2020, with no releases in roughly six years; this is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long period without visible maintenance.
Composer is used for builds, but no security scanning tooling is present, leaving a modest transparency and maintenance-hygiene gap.
The repository has no published security policy, so users have no documented channel or process for reporting security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elasticsearch/elasticsearch Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.