Organization backing and recent releases support continuity. Workflow images are unpinned, while the repository has no security policy or security scanning.
61%
Total Score
83
100
83
50
Tests and a changelog are not expected in the published artifact, and their absence is therefore neutral. The artifact has no README, which is a minor consumer-transparency gap for a library, although the source structure provides substantial implementation context.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, even though the recent release and organization backing provide some counterevidence.
The repository has zero stars and one fork, indicating limited visible adoption. Popularity is supporting evidence only, so this modestly limits confidence rather than determining the verdict.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning reduces repository hygiene and supply-chain transparency.
The repository has no security policy. That leaves vulnerability-reporting and response expectations undocumented for a package used in CMS integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
netgen/openapi Version ^1.0.2 | — | — |
netgen/layouts-core Version ^1.4.11 | — | — |
netgen/layouts-ibexa Version ^1.4 | — | — |
netgen/ibexa-site-api Version ^6.2 | — | — |
symfony/polyfill-php84 Version ^1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.