Its small audience and missing security policy leave less independent evidence for long-term support. Recent releases and a working test suite provide useful counterweight, but pinning this pre-1.0 version is prudent.
68%
Total Score
50
83
75
There were no commits and no active maintainers in the last 3 months. Although the package released recently, the lack of current source activity lowers maintenance confidence.
The repository has no stars or forks and only one watcher. Popularity is supporting evidence rather than a verdict, but this provides little external validation.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, making vulnerability reporting and response expectations unclear.
The release is not marked prerelease, but it remains on the 0.2 minor line, so compatibility expectations are less mature than for a stable major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cry/cry-cms-curl Version ^v0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.