Simple blogging system built on GibbonCms
35%
Total Score
unhealthy
Risky: no release or repository activity since May 2015, despite an unarchived and properly licensed project.
The latest release was in May 2015, and there have been no releases in the last 12 months despite the package being over 11 years old. This is strong evidence of abandonment for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
Composer is used as the build tool, but no security scanning tools are reported. Given the package's long inactivity, the missing scanning is a minor hygiene concern rather than the primary risk.
The repository is not archived, which is a small positive, but its last push was still in May 2015 and does not offset the prolonged inactivity.
The repository has no formal security policy. The README provides an email contact for security reports, which partly compensates for the missing policy but leaves disclosure guidance limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~2.6 | — | — |
gibboncms/gibbon Version ~0.1 | — | — |
league/commonmark Version 0.8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.