Its README explains the package’s purpose and compatibility, while the single runtime dependency and absence of install scripts keep adoption simple. The repository is small and lacks security scanning, so maintenance confidence remains limited.
52%
Total Score
67
100
75
83
The repository had zero commits and zero active maintainers in the last 3 months, consistent with maintenance having stopped around December 2020. This is a significant abandonment concern.
The artifact includes a license file, but it was detected as GPL-3.0 while the manifest declares LGPL-3.0+, leaving a material licensing mismatch to resolve before adoption.
The package has four releases since October 2016, but none in the last 12 months; version 3.1 was released in December 2020, about 5 years and 9 months ago. This strongly lowers confidence in ongoing maintenance.
The repository has 3 stars and 1 fork, indicating limited adoption evidence. Popularity is only supporting evidence, so this modestly reduces maturity confidence rather than deciding the verdict.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a hygiene gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/flow Version ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.