The latest release is recent and the repository is active enough to avoid abandonment concerns. Long gaps between releases, no recent commits, and missing licensing and security documentation reduce confidence for a long-term dependency.
62%
Total Score
50
100
75
50
No license declaration, license file, or repository license file was detected, leaving the legal terms for reuse unclear.
The package has existed for about 7 years with 6 releases and a median interval of about 405 days, indicating a slow release cadence, although a release was published recently.
The repository recorded no commits and no active maintainers in the past 3 months, weakening the evidence of ongoing maintenance despite the recent release.
The repository name does not match the package name and its README was not found to mention the package; because the owner is an organization, this may reflect packaging structure but still leaves repository ownership less clear.
Composer build tooling is present, but no security scanning tools were detected, leaving supply-chain hygiene less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
open20/amos-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.