Central ownership and a clear consumer README reduce uncertainty for this read-only theme mirror. The absent license and sparse project activity still make long-term dependency use harder to justify.
58%
Total Score
75
75
50
No license declaration or license file was found in the package or repository, leaving the legal terms for reuse unclear.
The package has existed for about 5 years with 86 releases, but only 1 release in the last 12 months and a median interval of about 385 days indicate sparse maintenance.
The repository had 0 commits and 0 active maintainers in the last 3 months. A push occurred recently and the README identifies this as a centrally managed read-only mirror, which partly offsets concern but does not show current development capacity here.
No security policy was found. This is a modest transparency gap, while the repository's organizational backing and clean workflow audit provide some context.
The single workflow uses a pull_request_target trigger without an untrusted checkout or script-injection sink, but its one action reference is unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mautic/core-lib Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.