The tiny README offers little integration guidance, while the repository has no security policy or scanning. Apache-2.0 licensing and a small runtime dependency footprint reduce adoption friction, but do not provide current maintenance assurance.
38%
Total Score
0
100
64
75
The package has made only one release, on June 28, 2020, with no releases in the last six years. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and materially weakening maintenance confidence.
A README is present, but it is only 20 characters and provides minimal consumer guidance. The absence of published tests and a changelog is normal packaging practice and is not itself a concern.
Composer is used for the build, which is appropriate, but no security-scanning tools are configured. This is a modest assurance gap rather than evidence of unsafe behavior.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This adds transparency risk, especially for a package with no recent maintenance evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lsys/config Version ~0.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.