Recent releases and a matching, tested repository show active project work and solid packaging. The registry withdrawal still makes this release a poor long-term dependency choice.
24%
Total Score
50
83
50
Packagist marks the entire package as abandoned, with no replacement listed; this is a severe adoption and continuity warning despite other signs of activity.
There were no commits and no active maintainers in the last 3 months, which conflicts with the recent registry release cadence and indicates uncertain ongoing development.
The repository has no security policy. This is a transparency gap, although the available workflow audit found no high- or medium-severity issues.
Both workflows were analyzed without dangerous triggers or audit findings, but all 11 action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elgg/elgg Version ~7.0.0 | — | — |
composer/installers Version ^2.0 | — | — |
mrclay/elgg-url-sniffer Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.