The package is licensed and has no install-time scripts, while its README leaves installation and configuration unfinished. The linked repository does not identify the package in its README, weakening confidence in its provenance.
18%
Total Score
0
50
50
This is the only release, published over 11 years ago, with no releases in the last 12 months. That strongly indicates abandonment for a dependency intended for ongoing use.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long gap since its last release and indicating no current maintenance capacity.
A README is present, but its installation and configuration sections contain TODOs. Tests and a changelog are absent from the published artifact, which is normal packaging practice and not counted against it.
The linked repository name does not match the package name, and its README does not mention the package. That weakens confidence that the repository is the authoritative source, even though name differences can occur in subpackages.
The repository has one star, zero forks, and one watcher. Popularity is only supporting evidence, but these counts provide little independent evidence of adoption or community maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ekyna/cms-bundle Version 0.1.*@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.