The small README and absent repository tests limit documentation and validation, while the organization-backed project remains licensed and unarchived. Its stable release history is substantial, but no release has appeared for over two years, so pinning this version warrants care.
62%
Total Score
75
50
81
50
Seven runtime dependencies create a relatively broad dependency surface for a library, increasing the amount of upstream maintenance this release relies on.
The artifact includes a README and this version has a GitHub release; missing tests and changelog files are normal packaging practice and are not negative findings on their own, though the README is only 72 characters.
The package has 32 releases since February 2020, but none in the last two years; the long pause is a meaningful maintenance concern despite its earlier regular cadence.
There are no open issues or pull requests, and no recent activity; this is consistent with a quiet project but provides little evidence of active support.
The repository uses Composer, but no security-scanning tooling is present, leaving automated dependency or code checks unverified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
orpheus/orpheus-core Version ^4.0.0 | — | — |
orpheus/orpheus-yaml Version ^4.0.0 | — | — |
orpheus/orpheus-cache Version ^4.0.0 | — | — |
orpheus/orpheus-webtools Version ^4.0.0 | — | — |
orpheus/orpheus-publisher Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.