The package has had no release since February 2023 and no recent commits, while its repository has no stars or forks. It is licensed, includes repository tests, is backed by an organization, and is not deprecated or archived.
58%
Total Score
50
78
50
There were zero commits and zero active maintainers in the preceding three months, consistent with the multi-year release gap. This is the strongest evidence of currently inactive maintenance.
The package runs post-install and post-update Composer scripts, adding execution during dependency operations. This is a supply-chain hygiene concern even though the signal does not establish malicious behavior.
The latest release was in February 2023, with no releases in the last 12 months, indicating a long period without published maintenance. The package is established rather than newly abandoned, but the gap is significant.
The repository name does not match the package name and its README does not mention the package, so the repository may not clearly identify this package as its product. The source layout and organization relationship provide limited context but do not remove the transparency concern.
The repository has zero stars and forks and only one watcher, showing little visible adoption or external review. Low popularity is supporting caution rather than proof that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
enjoyscms/core Version ^4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.