The package is clearly licensed, compact, and backed by an organization, with no install-time scripts or registry deprecation. Maintenance evidence is weak, and the alpha release status plus missing security policy add adoption risk.
45%
Total Score
50
64
50
The latest release was published in November 2021, with no releases in the following 12 months of the observed history. This long release gap materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months of the observed period. This supports the broader evidence of inactive maintenance.
The repository has zero stars and forks, with four watchers. Low visibility provides little supporting evidence of community review or adoption, although popularity is not decisive by itself.
Composer is used for builds, but no security-scanning tooling is present. The absence of scanning is a modest supply-chain hygiene gap, not evidence of malicious behavior.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a meaningful transparency gap for a package that can add tracking behavior to an application.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cmsgears/module-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.