The package includes a usable README and changelog, and its stable release is not registry-deprecated. Organization backing offers some continuity, but there is little evidence of current oversight.
40%
Total Score
50
50
69
50
The latest release was published in May 2023, with no releases in the last 12 months. This is a substantial abandonment concern for a package intended as an application extension.
The repository has no commits and no active maintainers in the last three months, reinforcing the long release gap rather than showing ongoing maintenance.
The package declares 20 runtime dependencies and no development dependencies, creating a broad runtime dependency surface. The profile is not inherently unsafe, but it increases maintenance burden for an already inactive package.
No license is declared, and neither the package nor the linked repository contains a detected license file. This creates a material legal and transparency gap for adoption.
The linked repository name does not match the package name, and README mention status is unknown. The mismatch makes package ownership less transparent, although the organization-backed repository provides some context.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pkpass/pkpass Version ^1.2.4 | — | — |
open20/amos-core Version ^1.20.0 | — | — |
open20/amos-admin Version ^2.2.0 | — | — |
kartik-v/yii2-mpdf Version * | — | — |
open20/amos-comuni Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.