The package is clearly licensed, documents this release well, and keeps runtime dependencies limited. Recent commits and organization backing provide some continuity, but the linked repository does not identify the package and has no security policy.
64%
Total Score
83
100
81
83
There have been only 2 releases across about 2 years and 7 months, with a median interval of about 2 years and 5 months; one release in the last 12 months shows activity but a sparse cadence.
All 8 recent commits came from one contributor, leaving a thin maintenance base; organization ownership provides some handoff capacity but does not remove the concentration risk.
The repository name does not match the package name and its README does not mention the package, creating a caution that the repository linkage may be unclear; the organization backing does not resolve that transparency gap.
Composer build tooling is present, but no security-scanning tooling is reported, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented security reporting or response process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
formatd/hotspot-editor Version ~3.0 | — | — |
neos/nodetypes-basemixins Version ~9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.