The package is small and clearly licensed, with a repository matching its package name and organization backing. Its missing security policy and security scanning provide limited transparency for future maintenance.
42%
Total Score
75
100
71
75
The latest release was published in November 2021, and there have been no releases in the last 12 months. This long release gap materially raises abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the prolonged release gap and limited evidence of ongoing maintenance.
Composer is used for builds, but the repository reports no security-scanning tools. For a maintained dependency, this is a transparency and maintenance-hygiene gap.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a modest transparency concern, not evidence of unsafe code.
The assessed version is still an alpha release, and all recent releases were prereleases. That indicates the package has not demonstrated stable release maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cmsgears/module-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.