The setup guide and release notes help users get started, and the repository remains unarchived. However, the project has had no release or commit activity for about 9 years, while its declared GPL-3.0+ license conflicts with the repository's detected MIT license.
38%
Total Score
0
60
50
The latest release was published about 9 years ago, with no releases in the last 12 months. This strongly suggests abandonment despite the package having three historical releases.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and leaving current maintenance unverified.
The manifest declares GPL-3.0+, while the repository license file is detected as MIT. Although a repository license exists, the mismatch creates genuine legal and provenance uncertainty.
The package runs post-install and post-update Composer scripts. These are relevant supply-chain exposure during installation and should be inspected before adoption, though their presence alone does not show harmful behavior.
Composer is used for builds, but no security scanning tools are reported. This is a maintenance and assurance gap, though it is less significant than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/seo Version ~2.0 | — | — |
neos/neos Version ~3.0.0 | — | — |
neos/setup Version ~4.0 | — | — |
neos/nodetypes Version ~3.0.0 | — | — |
neos/site-kickstarter Version ~3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.