The package is small and focused, with a minimal artifact and one runtime dependency. Organization backing and a recent repository update provide continuity, but maintenance remains concentrated and security documentation is limited.
68%
Total Score
67
100
88
75
The package has existed for about 5 years 8 months but has only five releases, with a median interval of about 17 months and one release in the last 12 months. The recent v9.11.0 release is positive, but the long intervals indicate a slower maintenance cadence.
All two recent commits came from one contributor, so maintenance capacity is concentrated. The organization-owned repository provides some ability to hand maintenance off, partly offsetting that risk.
The repository recorded two commits in the last three months, showing recent activity, but the volume is modest for a package with a long release interval.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a documentation gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openpsa/midcom-core Version ^9.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.