The package includes tests, a changelog, release notes, and a matching repository owned by an organization. Its single maintainer, minimal adoption, missing security policy, and post-autoload-dump script leave more operational risk than a mature dependency.
62%
Total Score
100
83
50
The package runs a post-autoload-dump lifecycle script during Composer installation. This is a meaningful installation-time behavior that deserves review, though the signal does not show that it is unsafe.
The latest release was published on February 21, 2025, with no releases in the following 12 months despite ten releases overall; this indicates stalled maintenance for a CMS package.
The repository has one star, no forks, and one watcher, showing very limited external adoption and review. This is supporting caution rather than proof that the package is unmaintained.
Composer is used as the build tool, but no security scanning tooling is present. For a package handling an administrative CMS surface, that reduces transparency around ongoing security checks.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.