The MIT license and matching repository make the package transparent to inspect. Its small dependency set and clean install path help, while the missing security policy leaves fewer signals about response readiness.
45%
Total Score
0
100
69
75
The latest release was over five years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite five total releases and a previously regular cadence.
There were no commits and no active maintainers in the measured three-month period. Combined with the last push being over five years ago, this materially raises abandonment risk.
The artifact includes a README, but it is only 10 characters long and offers little integration guidance. The absence of tests and a changelog in the published package is normal packaging practice, while the repository also provides neither.
Composer build tooling is present, but no security-scanning tools were detected. That is a moderate transparency and maintenance gap for a package with no recent activity.
The linked repository is not archived, so it remains technically available for inspection and possible maintenance. Its last push was over five years ago, however, which is consistent with the stale release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opxcms/opx-foundation Version ^1.1.4 | — | — |
opxcms/admin-authorization Version ^1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.