It has clear licensing, a substantial README, and a stable major release with release notes. The small dependency surface and organization backing help, but the overall maintenance picture remains weak.
42%
Total Score
50
100
75
100
Packagist marks the entire package as abandoned and names neos/form-yamlbuilder as its replacement. This is a direct adoption risk even though the assessed release itself is not merely withdrawn.
The repository recorded zero commits and zero active maintainers in the last three months. That is a material abandonment concern, only partly offset by the recent package release and repository push.
There were no new or closed issues and no merged pull requests in the last month, while 10 issues and 7 pull requests remain open. This indicates limited current project activity.
The repository name does not exactly match the package name and its README does not mention the package, creating uncertainty about package-to-repository ownership. The naming difference may be normal for a related package, but the missing README mention remains a caution.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/form Version ^5.0 || ^6.0 | — | — |
neos/neos Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.