Usable with caveats: it is actively developed and has tests, clear licensing, and organizational backing, but it is only 48 days old and all recent commits come from one contributor. The lack of security scanning and a security policy adds transparency risk.
68%
Total Score
75
100
78
90
Six releases in the last 48 days, with a median interval of about 18 hours, show active delivery but provide limited evidence of long-term maturity because the package is very new.
One contributor made 100% of the 19 recent commits. Organizational backing partly offsets the handoff risk, but the observed maintenance capacity remains concentrated.
The repository received 19 commits in the last 3 months, but all were made by one active maintainer. The activity is strong, while the narrow contributor base limits continuity.
The repository has only 2 stars and no forks or watchers, indicating limited external adoption. This is supporting evidence of low maturity, not a verdict by itself.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning reduces assurance for a dependency intended for production projects.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/diff Version * | — | — |
neos/neos Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.