The artifact declares GPL-2.0+ but contains an MIT license file, creating a licensing question. Organization backing and a non-archived repository help, but the project has little recent activity and no security policy.
45%
Total Score
100
100
60
50
The package has only two releases, both from May 2018, with no release in more than eight years. This is strong evidence of abandonment risk for a dependency.
The manifest declares GPL-2.0+, while the only detected license file is MIT and belongs under Vendor/Scss. That mismatch should be resolved before adoption because the package's effective licensing is unclear.
The repository is not archived, which is a positive sign, but its last push was in July 2019, leaving substantial evidence of inactivity despite its open status.
The linked repository has no security policy. This weakens transparency and incident-reporting readiness, although the absence alone is not evidence of a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafo/scssphp Version ^0.7.4 | — | — |
typo3/cms-core Version 8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.