The small dependency set and clear README reduce integration friction. Organization backing and a recent release help, but the long release gaps, limited recent activity, and missing license and security documentation weaken confidence.
64%
Total Score
75
100
81
50
No declared license, license file, or repository license file was detected. This creates a real legal and transparency gap for adoption.
The package has only 3 releases since June 2020, with a median interval of about 2 years and 10 months; only 1 release appeared in the last 12 months. The February 2026 release shows it is not abandoned, but the overall cadence is sparse.
There were 0 commits and 0 active maintainers in the last 3 months. The recent release partly offsets this, but the current maintenance capacity is not demonstrated.
Composer is used for the build, which fits the Packagist ecosystem, but no security scanning tool is configured. This is a modest transparency and maintenance weakness.
The repository has no security policy. This does not make the package unusable, but it leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
open20/amos-core Version >=1.9 | — | — |
open20/amos-notify Version >=1.4 | — | — |
softark/yii2-dual-listbox Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.