The organization-backed repository is licensed, linked to the package, and includes a usable README. Missing security scanning and policy make maintenance transparency thinner.
58%
Total Score
75
86
75
The package has seven releases over about 28 months, but none in the last 12 months; the latest release was about 16 months ago. This indicates materially slowed maintenance, despite a previously regular release interval.
The repository recorded no commits and no active maintainers in the last 3 months. That weakens evidence of ongoing maintenance and increases abandonment risk.
Composer build tooling is present, but no security-scanning tools are configured. The build setup is established while automated security coverage is limited.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a hygiene and maintenance concern, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
carbon/codepen Version ^0.2.11 | — | — |
carbon/webfonts Version ^0.1 | — | — |
carbon/rangeeditor Version ^0.1.11 | — | — |
litefyr/integration Version self.version | — | — |
carbon/editor-styling Version ^0.1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.