The package is clearly identified, stable, and has a small dependency surface. Maintenance is recent but sparse and concentrated in one contributor, while the organization backing and recent publication reduce abandonment concerns. Missing security documentation leaves a meaningful transparency gap.
65%
Total Score
67
100
83
75
The package has existed for about 6 years but only 5 releases, with one release in the last 12 months and a typical gap of about 19 months. This indicates slow maintenance rather than abandonment, so it lowers confidence without making the release unfit.
All 2 recent commits came from one contributor, so maintenance is concentrated. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
The repository received 2 commits in the last 3 months from one active maintainer. Recent activity is positive, but the low volume provides only modest evidence of ongoing maintenance.
The repository has 0 stars, 0 forks, and 1 watcher. This offers little community validation, but popularity is supporting evidence rather than a health verdict, especially for a specialized package.
Composer is used for the build, which fits the package ecosystem, but no security scanning tool is present. The missing scanning reduces assurance modestly rather than indicating abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openpsa/midcom-core Version ^9.11.0 | — | — |
openpsa/org-openpsa-widgets Version ^9.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.