The README is only 149 characters and leaves installation and configuration marked TODO, while the repository has no tests or security scanning. Its MIT license and lack of install scripts are positive, but they do not offset the weak documentation and project hygiene.
35%
Total Score
50
100
63
75
The package has only one release, first and latest published in June 2015, with no releases in the last 12 months. This is strong evidence of abandonment for a library dependency.
The repository recorded zero commits and zero active maintainers in the last three months. With the package last released in 2015, this supports a substantial abandonment concern.
The artifact includes a README, but it is only 149 characters and leaves installation and configuration as TODOs. Missing tests and a changelog are normal for published artifacts, while the repository also reports no tests or changelog.
The repository name does not match the package name according to the collected check, and its README does not mention the package. That creates uncertainty that the linked repository is the intended source.
Composer is used for the build, which is appropriate for a Packagist package, but no security scanning tools are present. The missing scanning is a hygiene gap rather than evidence of immediate unfitness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ekyna/cms-bundle Version 0.1.*@dev | — | — |
ob/highcharts-bundle Version ~1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.