Usable with caveats: the repository is active, tested, organization-backed, and not archived, but this release is nearly seven years old and the package has had no registry release in that time. Missing security policy and workflow permission declarations add smaller transparency concerns.
70%
Total Score
90
100
89
75
The package has only two releases, with the latest published nearly seven years ago and none in the last 12 months. That weak registry release cadence lowers confidence that this exact artifact is kept current, despite recent repository activity.
There are no open issues and one open pull request, but no issues or pull requests were merged in the last month. This is a minor activity concern rather than evidence of abandonment.
Four stars and no forks indicate a small user and contributor community. This is supporting caution about external validation, not a maintenance verdict by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is not evidence that the package is unsafe.
The repository workflow does not declare top-level token permissions. Although no write permissions were observed, explicit least-privilege settings would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/event-dispatcher Version >=2.8.26 | — | — |
detain/myadmin-plugin-installer Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.