It has a clear BSD-3-Clause license, a matching source repository, upstream tests, and release notes for this version. One registry maintainer and no security policy limit confidence in ongoing support.
58%
Total Score
67
80
50
The latest release was in March 2017, about 9 years ago, with no releases in the last 12 months. This is strong evidence of a stale dependency, though the package has a stable release history rather than erratic publishing.
The package runs a post-autoload-dump lifecycle script during installation, adding install-time behavior that consumers should account for. No provided evidence shows that the script is unsafe.
Only one account has registry publish access. That is less concerning because the source repository is organization-owned, but it still indicates a thin publishing base.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. This materially raises abandonment risk.
The repository has no security policy, leaving reporting and response expectations undocumented. This is a transparency gap, not evidence of a security incident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
icybee/core Version ^3.0 | — | — |
icybee/module-registry Version ^3.0 | — | — |
icanboogie/module-installer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.