An organization backs the repository, it is not archived, and the README explains installation. Explicit dependencies and a working Composer build help, but the project provides limited operational transparency.
58%
Total Score
75
75
50
No license is declared, no license file is present in the package, and the linked repository also has no license file. This leaves the release without clear reuse terms.
The package has existed for about seven years with 13 releases, but only one release appeared in the last 12 months. That indicates a slow maintenance cadence, partly offset by the latest release being published recently.
The repository recorded no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the release history shows the project has not stopped publishing entirely.
The repository uses Composer for its build or package workflow, but no security scanning tools were detected. The build tooling is appropriate; the absent scanning is a modest transparency gap.
The linked repository has no security policy. This weakens vulnerability-reporting transparency, though it does not by itself indicate abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
open20/amos-core Version ^1.48.0 | — | — |
open20/amos-admin Version >=1.8 | — | — |
open20/amos-layout Version ^1.11.1 | — | — |
open20/amos-dashboard Version ~1.5 | — | — |
lispa/yii2-tree-manager Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.