A changelog, stable version, and organization-owned repository provide useful context. The package is easy to install without lifecycle scripts, but transparency and maintenance evidence remain limited.
58%
Total Score
75
100
75
75
No license is declared, no license file is included, and no repository license file was detected. This leaves the legal terms for using the package unclear.
The package is over seven years old and has a release as recent as January 2026, but only one release appeared in the last 12 months. This suggests limited ongoing release activity rather than abandonment by itself.
The repository had no commits and no active maintainers in the last three months. Although a recent release exists, the lack of recent source activity weakens evidence of active maintenance.
The repository name does not exactly match the package name, and no README mention was available. The related naming and organization backing make a monorepo or subpackage explanation plausible, so this is only a mild identity concern.
Composer is used for the build, which fits the package ecosystem, but no security scanning tooling was detected. This is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
open20/amos-core Version ^1.25.1 | — | — |
open20/amos-admin Version ^2.2.0. | — | — |
open20/amos-notify Version ^1.4 | — | — |
open20/amos-workflow Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.