Documentation, tests, and a maintained source repository provide useful support for adoption. Recent commit activity is absent, and all 11 workflow actions are unpinned; the missing security policy adds a smaller transparency concern.
68%
Total Score
50
100
89
83
The registry namespace and repository owner are both user-owned rather than organization-backed. This is not inherently unhealthy, but it provides less visible institutional maintenance capacity.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the recent push and release history provide some counterweight.
The repository has only two stars and one fork, indicating limited external adoption. Popularity is supporting evidence rather than a decisive health measure.
Composer is used as a build tool, but no security scanning tool was detected. The absence of scanning lowers repository hygiene modestly without showing abandonment.
No security policy was found in the repository, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elgg/elgg Version ~6.1.0 | — | — |
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.