The package includes an MIT license and substantial bundled assets, with no install-time scripts. Its README appears unrelated to AsgardCMS, and the dependency set is sizeable for a release whose maintenance cannot be verified.
39%
Total Score
50
70
100
Only two releases were published, both in 2019, with no release in nearly seven years. That long silence is strong evidence of abandonment risk for a core CMS dependency.
Eleven runtime dependencies create a meaningful maintenance surface for an old CMS core package. The profile is not inherently unsafe, but it increases the consequences of stale compatibility assumptions.
The artifact contains a README, tests, and a changelog, which is positive documentation and quality evidence; however, the README excerpt describes unrelated microplugin.js content, weakening its value for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tightenco/ziggy Version ~0.4 | — | — |
composer/installers Version ~1.0 | — | — |
laracasts/presenter Version ~0.2 | — | — |
floatingpoint/stylist Version ~1.0 | — | — |
laravelcollective/html Version ~5.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.