The stable major version, recent release notes, and organization-owned repository support continued project structure. Maintenance activity is currently quiet, and the linked repository does not identify this package in its name or README; its lack of a security policy is an additional transparency gap.
62%
Total Score
75
75
50
The package has existed for about 7 years with 12 releases, but only one release in the last 12 months. The latest release is recent, so this indicates a modest maintenance concern rather than abandonment.
The repository shows zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the recent release provides some contrary evidence.
The repository name does not match the package name and its README does not mention the package. It may still be a sub-package or monorepo component, but the ownership relationship is less transparent.
The repository uses Composer build tooling, but no security scanning tools were detected. For a small package this is a hygiene gap, not evidence of abandonment by itself.
No repository security policy was found. That reduces transparency for reporting and handling issues, though it is not a direct indication that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/flow Version ^8.0 || ^9.0 | — | — |
flownative/sentry Version ^2.0 || ^3.0 | — | — |
flowpack/jobqueue-common Version ~3.0 | — | — |
flowpack/jobqueue-doctrine Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.