Usable with caveats: the package is clearly licensed, documented, organization-backed, and not deprecated, but it has only two releases and no commits in the last three months. Its small, inactive repository and lack of security-policy or scanning evidence make long-term maintenance less certain.
58%
Total Score
83
100
78
88
The package is young at about 146 days old and has only two releases, both published within about 18 minutes, so there is limited evidence of sustained release maintenance.
There were zero commits and zero active maintainers in the last three months. For a package this new, that is a meaningful warning about stalled maintenance, even though it may be feature-complete.
The repository has only four stars and no forks or watchers, indicating limited visible adoption; this is supporting caution rather than a verdict because small infrastructure packages can remain healthy with low popularity.
Composer is used for the build, but no security-scanning tool is present. That is a transparency and maintenance gap, though it is not severe enough on its own to make the package unfit.
The linked repository is not archived, but its last push was about 146 days ago, which offers no evidence of recent maintenance by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos Version ^9 | — | — |
neos/timeable-node-visibility Version ^9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.