It has a clear MIT license, README, release notes, and no install-time scripts. However, the project shows no recent maintenance, has very little community activity, and lacks security scanning and a security policy.
42%
Total Score
50
100
72
75
The latest release was in March 2019, with no releases in the last 12 months and a median interval of about 549 days. This is strong evidence of stalled maintenance for a package still being considered for adoption.
The repository had zero commits and zero active maintainers during the last three months, consistent with the long release gap and indicating little current maintenance capacity.
There were no new or closed issues or pull requests in the last month, while one issue remains open. This supports the picture of an inactive project, though it is weaker evidence than the absent commits.
The repository has only 4 stars and 5 forks, so there is limited visible community adoption or backup. Popularity is supporting evidence rather than a verdict, but it offers little compensation for the maintenance gap.
Composer is used for the build, but no security-scanning tools are present. The absence of automated scanning is a modest hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lolautruche/embedtag-ls Version ~1.0 | — | — |
ezsystems/ezpublish-kernel Version ^5.3.0|^6.0|^7.0|>=2014.03 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.