A real repository, stable versioning, release notes, and repository tests provide useful support. The small project footprint and absent security policy leave less evidence for long-term care.
61%
Total Score
67
90
50
The package has 28 releases over roughly 10 years, but none in the last 12 months; the latest release was published about 15 months ago. This indicates a mature history but currently slow maintenance.
The repository had no commits and no active maintainers in the last three months. Although the latest release was pushed around 15 months ago, this recent inactivity weakens evidence of ongoing maintenance.
There are four open issues, with no new or closed issues and no merged pull requests in the last month. This is limited activity rather than evidence of abandonment on its own, but it provides little support for active upkeep.
The linked repository has no security policy. That reduces vulnerability-reporting transparency, though it is not by itself evidence that the package is unsafe.
Both workflows were analyzed successfully and have no untrusted checkouts or script injection, but all 9 action references are unpinned and one high-confidence medium-severity finding uses an archived action. This is a meaningful build-supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
netcommons/mails Version @dev | — | — |
netcommons/pages Version @dev | — | — |
netcommons/rooms Version @dev | — | — |
netcommons/users Version @dev | — | — |
cakedc/migrations Version ~2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.