Tests, licensing, and a small runtime dependency surface make the package reasonably straightforward to adopt. Organization backing and an unarchived repository help, but the project shows limited recent development and incomplete workflow hardening.
58%
Total Score
75
100
88
67
The latest registry release was on February 17, 2023, with no releases in the last 12 months; this indicates a long period without published updates and raises abandonment concerns.
There were no commits and no active maintainers in the last three months, which weakens evidence of ongoing maintenance despite the repository's more recent push timestamp.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and hygiene gap rather than evidence that the package is unmaintained.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
All three workflows were analyzed and contain no untrusted triggers or script-injection sinks, but all six action references are unpinned and a high-confidence finding reports an unpinned container image. This weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
netgen/content-browser Version ~1.4.0 | — | — |
ezsystems/ezplatform-admin-ui Version ^1.5 || ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.