Frequent releases over the last year suggest ongoing publishing, but every recent release is marked prerelease. The source repository has no commits in three months, lacks a security policy, and does not clearly identify this package.
55%
Total Score
50
81
83
The repository recorded zero commits and zero active maintainers in the last three months. Although registry releases are frequent, the absence of recent source activity is a meaningful maintenance concern.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked repository is the authoritative source for this release.
Composer is used for the build, but no security scanning tools were detected. This is a transparency and hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The assessed version is marked stable but is also a prerelease, and all recent releases are prereleases. That makes compatibility and change expectations less predictable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ~13.4.0 | — | — |
sjbr/static-info-tables Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.