The repository has no commits from active maintainers in the last three months, and it lacks security scanning and a security policy. Its long release history, recent registry releases, organization backing, tests, and clear licensing provide useful counterweight.
67%
Total Score
83
50
93
50
The package declares 37 runtime dependencies, including a substantial Ibexa and Netgen application stack; this is coherent for a website skeleton but increases upgrade and transitive-maintenance burden.
post-install-cmd and post-update-cmd run during Composer operations, adding install-time execution risk beyond ordinary file installation.
The repository recorded 0 commits and 0 active maintainers in the last three months, a meaningful sign of slowed development even though registry releases continue.
The project uses Make and Composer, but no security scanning tools were detected; that weakens the repository's ongoing supply-chain hygiene.
No SECURITY policy was found, leaving vulnerability reporting and disclosure expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ibexa/oss Version ~5.0.0 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
symfony/flex Version ^2 | — | — |
symfony/yaml Version 7.4.* | — | — |
netgen/toolbar Version ^2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.