The package has a long release history, tests, and a clear MIT license. Recent repository activity is absent, and the linked repository does not identify this package in its README. Organization backing and a recent release reduce, but do not remove, the maintenance concern.
68%
Total Score
75
100
83
83
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although a release was pushed recently, the lack of observed development activity still raises a maintenance concern.
There were no new or merged pull requests and no issue activity in the last month. This is consistent with the lack of recent commits, but the available issue count is incomplete, so it is supporting rather than decisive evidence.
The repository name does not match the package name, and its README does not mention the package. Although name differences can occur with subtree splits, the lack of any README reference makes package ownership less transparent.
The repository has 0 stars and forks and 2 watchers. Low popularity limits external validation, but popularity is only supporting evidence and does not outweigh the package's release and testing history.
Composer is used for builds, but no security scanning tools were detected. That is a modest repository hygiene gap, not evidence that the release is unmaintained.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
enhavo/metadata Version ^0.15 | — | — |
enhavo/app-bundle Version ^0.15 | — | — |
enhavo/form-bundle Version ^0.15 | — | — |
enhavo/routing-bundle Version ^0.15 | — | — |
league/uri-components Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.