The package is clearly identified, licensed, and backed by an organization. Recent repository work is reassuring, but releases are infrequent, activity rests with one contributor, and no security policy or scanning is present.
70%
Total Score
88
100
83
83
The package has five releases over about 5 years and 9 months, with one release in the last 12 months; the roughly 533-day median interval indicates a slow maintenance cadence.
All four recent commits came from one contributor, leaving maintenance dependent on a single active person. Organization backing provides some handoff capacity, but no second active contributor is shown.
The repository has no stars or forks and one watcher, indicating limited public adoption. Popularity is supporting evidence only and does not outweigh the recent maintenance and organization backing.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no documented security policy, so there is no visible process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openpsa/midcom-core Version ^9.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.