This release is usable but warrants caution. The package has a long history since 2019, 47 releases including 14 in the last 12 months, a stable non-prerelease version, no registry deprecation, an explicit LGPL-2.1-or-later license, organization backing, and no install-time scripts. However, the linked repository is unusually minimal, with only three files and no tests or changelog, shows no commits or active maintainers in the last three months, has no security policy or security-scanning tooling, and has negligible repository adoption. Recent registry releases provide evidence of ongoing publishing, but the lack of visible development activity and project hygiene reduces confidence in long-term maintenance and transparency.
63%
Total Score
75
100
83
80
The artifact and repository each contain only .gitignore, README.md, and composer.json. This may be appropriate for a Composer distribution wrapper, but it provides little source or validation context for the release.
A useful README explains that this is a standard-component distribution and documents installation, but both the artifact and repository lack tests and a changelog, leaving maintenance and release transparency less well supported.
The repository reports zero commits and zero active maintainers in the last three months. Recent package releases partly compensate for this gap, but the absent source-development activity remains a meaningful maintenance concern.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently unhealthy, but combined with the minimal repository it offers little evidence of active community maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little external evidence of community adoption or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jelix/jelix Version 1.8.27 | — | — |
jelix/feeds-module Version ~1.7.6 | — | — |
jelix/wikirenderer-plugin Version ~1.7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.