The package is a focused theme with a clear README and no install-time scripts. Its missing license and unpinned workflow action reduce transparency and reproducibility, while recent repository inactivity is partly offset by frequent registry releases and organization backing.
68%
Total Score
75
100
86
67
No license declaration or license file was detected in the package or repository, leaving the terms for using this theme unclear.
The repository recorded no commits from maintainers in the last three months, which is a maintenance concern, though the strong registry release cadence indicates activity is managed centrally elsewhere.
Composer is used for builds, but no repository security scanning tool was detected; this is a modest transparency gap rather than evidence of abandonment.
The repository has no published security policy, reducing transparency about vulnerability reporting and handling.
The single workflow uses a pull_request_target trigger without an untrusted checkout or script-injection sink, but its only action reference is unpinned. The audit completed fully and found no other reported issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mautic/core-lib Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.