Risky to adopt: the release and repository have seen no activity for more than five years, making abandonment and compatibility problems likely. It has tests, a README, stable versioning, and organizational backing, but those positives do not offset the prolonged inactivity.
45%
Total Score
50
67
50
The package has had no releases in more than five years, with only four releases overall and a median interval of about 438 days. This is strong evidence of an unmaintained dependency despite its long history.
There were zero commits and zero active maintainers in the last three months, consistent with the release history showing no release in more than five years. This materially raises abandonment risk.
There were no new or closed issues or pull requests in the last month, and no open work remains visible. Combined with zero recent commits, this indicates an inactive project rather than an actively maintained quiet period.
The repository name does not exactly match the package name and its README does not mention the package, so the linkage is less transparent. The repository file tree nevertheless contains the AuthShibboleth implementation and tests, which partly supports the association.
Composer is used for the build, providing expected package tooling, but no security scanning tools were detected. The absence of scanning is a modest hygiene concern rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
netcommons/mails Version @dev | — | — |
netcommons/users Version @dev | — | — |
cakedc/migrations Version ~2.2 | — | — |
netcommons/net-commons Version @dev | — | — |
netcommons/site-manager Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.