Healthy and suitable to depend on. It has a long release history, a current stable release, active repository maintenance, clear licensing, tests, and organization backing; maintenance is concentrated in one recent contributor and workflow permissions are not explicitly restricted.
84%
Total Score
88
100
94
88
One contributor made all 7 commits in the last 3 months, creating a concentration risk. Organization backing provides some handoff capacity, but no second recent contributor is shown.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and defense-in-depth gap, partly offset by the repository's other maintenance evidence.
The one workflow has no top-level permissions declaration, so its token access is not explicitly minimized. No write permissions were observed, but the missing restriction is a workflow hygiene caution.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-32697 neos/form is vulnerable to Improper Input Validation in versions 1.2.0 - 4.3.3, 5.0.0 - 5.0.9 and 5.1.0 - 5.1.3. | 1.2.0 - 4.3.35.0.0 - 5.0.95.1.0 - 5.1.3 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/flow Version ^8.4 || ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.