This is a usable, established package with a stable release, an explicit GPL-2.0-only license, organization backing from Elgg, a matching repository, tests, and a recent release and repository push. However, maintenance activity is uneven: the repository shows no commits or active maintainers in the last 3 months, 33 open issues with no issues closed in the last month, and no security scanning or security policy. The package is not deprecated or archived, and its recent release activity partially offsets the repository-activity concerns, but adopters should expect a relatively thin maintenance and security-transparency posture.
68%
Total Score
75
100
94
90
The repository recorded 0 commits and 0 active maintainers over the last 3 months. The recent release and push provide some compensating evidence, so this is a maintenance caution rather than a severe abandonment finding.
There are 33 open issues, with no new or closed issues in the last month and no open pull requests; this suggests unresolved maintenance backlog despite one merged pull request.
Composer build tooling is present, but no security-scanning tools are configured, leaving a security-transparency and automated-review gap.
The repository has no SECURITY policy, reducing transparency around vulnerability reporting and coordinated maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bower-asset/flot Version ~0.8 | — | — |
bower-asset/chosen Version ~1.6 | — | — |
composer/installers Version >=1.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.