The package is clearly licensed, has a matching source repository, and keeps its runtime dependency surface small. Organization backing helps, but the lack of security policy and scanning leaves limited assurance for future maintenance.
48%
Total Score
50
100
72
88
Only two releases exist, with no release in nearly three years; this is a substantial maintenance and abandonment concern for a dependency.
There were no commits and no active maintainers in the last three months, reinforcing the release-history evidence of a dormant project.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a very small project but does not demonstrate active maintenance.
The repository has no stars or forks and only one watcher. Low popularity is supporting evidence rather than a verdict, but it offers little external adoption evidence.
Composer is used as a build tool, but no security-scanning tools are configured. The missing scanning is a modest transparency gap for ongoing maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mecha-cms/x.page Version ^3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.