The BSD-3-Clause license, tests, README, and organization-backed repository provide useful maintenance and usage context. The small dependency set and package-repository match reduce integration concerns, but the absent security policy and install-time script leave additional review work.
42%
Total Score
50
75
50
The package has had only 3 releases, with the latest published nearly six years ago and none in the last 12 months. This is strong evidence of abandonment risk despite the short historical release interval.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. That materially lowers confidence in ongoing maintenance.
The package defines a post-create-project-cmd install-time script. Such scripts can be legitimate, but they add execution and review surface when adopting an otherwise stale package.
The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external adoption signal to offset the stale maintenance record.
Composer is used for builds, but no security scanning tools are present. This is a hygiene gap rather than evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
oneplace/oneplace-core Version ^1.0.19 | — | — |
phpoffice/phpspreadsheet Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.