The MIT license, small dependency surface, and no install scripts reduce adoption friction. The organization-backed repository is active, but maintenance is concentrated in one contributor and the release history is stale.
64%
Total Score
75
100
83
83
The package has 10 releases over about 9 years, but no registry release in nearly three years. The recent repository push provides some compensating evidence, but release maintenance remains slow.
One contributor made all commits in the last three months. Organization backing partly reduces the risk, but current activity is still concentrated in one person.
Only one commit was recorded in the last three months, so activity exists but is very limited and does not demonstrate a strong maintenance cadence.
The repository has 3 stars and 2 forks. This is limited adoption evidence, but popularity is supporting context rather than a health verdict.
Composer is used for builds, but no security scanning tooling is reported. The missing scanner is a modest transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos Version ^4.0 || ^5.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.