The package is licensed, tested, documented, and not deprecated, with two recent contributors. Its small public footprint and missing security policy leave less evidence for long-term support.
61%
Total Score
75
79
75
The repository name does not match the package name and its README does not mention the package, so the source-package relationship is not clearly established.
Only two commits were recorded in the last three months. Two active contributors provide some continuity, but the observed maintenance activity is limited.
The repository has zero stars and forks and only one watcher. This is supporting evidence of a small project, not a health verdict by itself.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Both workflows were analyzed without dangerous triggers or audit findings, but all 11 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elgg/elgg Version ~7.0.0 | — | — |
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.