The package has a clear README, a Composer build, and recent publishing activity. Its tiny project footprint and lack of a documented security process leave less evidence for long-term support.
55%
Total Score
50
50
78
67
Six runtime dependencies, including three related project packages, create a meaningful dependency surface for this small library but do not by themselves indicate an unsafe design.
The repository is owned by an individual user rather than an organization, so the concentrated maintainer and contributor activity is not visibly backed by a broader team.
One contributor made all recent commits, leaving maintenance highly concentrated and increasing abandonment risk if that contributor becomes unavailable.
Only one commit was recorded in the last three months. Recent publishing helps, but this is thin evidence of ongoing development capacity.
The repository name does not match the package name and its README does not mention the package, making the source-to-package relationship less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cry/cry-cms-db Version ^1.10 | — | — |
cry/cry-cms-html Version ^1.06 | — | — |
cry/cry-cms-thing Version ^2.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.