The package has clear licensing and release documentation. Its only release was published about three years ago, with no recent commits, and the linked repository does not match the package name.
38%
Total Score
0
70
50
This package has only one release, published about three years ago, with no releases in the last 12 months. That is strong evidence of an inactive dependency.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and raising abandonment risk.
The package runs a post-autoload-dump install-time script, adding installation behavior that consumers must trust and account for. No other provided signal compensates for this extra execution surface.
The linked repository is named ruyicmf rather than kavience/ruyicms, and no package mention was found in its README. This may be a subpackage relationship, but ownership of this package is not clearly established.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities. The absence is a secondary concern alongside the stronger inactivity signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kavience/ruyicmf-api Version ^6.0.0 | — | — |
kavience/ruyicmf-app Version ^6.0.0 | — | — |
kavience/ruyicmf-root Version ^1.0 | — | — |
kavience/ruyicmf-install Version ^6.0.0 | — | — |
kavience/ruyicmf-appstore Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.