Usable with caveats. The package is actively published by an organization and has a current stable release, but its low release cadence, no commits in the last three months, and lack of security tooling or policy reduce confidence in ongoing maintenance.
68%
Total Score
88
100
88
88
The package has existed for about 4 years and released twice in the last 12 months, but its median interval is about 186 days, indicating a relatively slow maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful concern for a security-focused package despite the recent release and push.
Composer build tooling is present, but no security scanning tools were detected. That weakens ongoing transparency for a package whose purpose concerns backend security.
The repository has no security policy, leaving users without a documented channel or process for reporting vulnerabilities in a security-focused package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.