The package includes tests, a changelog, a matching repository, and a security policy, while organization backing and MIT licensing improve transparency. Its seven runtime dependencies and lack of repository security scanning add maintenance overhead.
58%
Total Score
75
88
100
The latest release was in October 2020, with no releases in nearly six years despite 35 releases overall. This is strong evidence of stalled maintenance for a dependency released at that age.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating limited current maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected. That leaves a meaningful transparency and maintenance gap for a package with seven runtime dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
h5p/h5p-core Version ^1.24 | — | — |
h5p/h5p-editor Version ^1.24 | — | — |
guzzlehttp/guzzle Version ^6.2 | — | — |
laravel/framework Version 5.8.* | — | — |
twbs/bootstrap-sass Version @stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.