Lingoda Thinkingcap Bundle
62%
Total Score
caution
Usable with caveats: recent releases are offset by thin maintenance and a proprietary license.
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. That limits transparency and makes this a poor fit for an open-source dependency despite the explicit declaration.
One contributor made 100% of the single commit in the last 3 months. Organization backing helps provide handoff capacity, but the recent observed activity remains concentrated.
Only 1 commit was recorded in the last 3 months. Recent releases compensate for some of this concern, but the observed source-maintenance activity is limited.
The repository uses Composer build tooling but reports no security-scanning tools. This is a modest transparency and maintenance concern, not a severe risk by itself.
The repository has no security policy. For an API integration package, that reduces the documented path for reporting issues, though it does not show abandonment on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.7 | — | — |
symfony/yaml Version ^7.0 || ^8.0 | — | — |
phpro/soap-client Version ^4.0 | — | — |
symfony/http-client Version ^7.0 || ^8.0 | — | — |
symfony/framework-bundle Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.