The stable release, small dependency surface, and organization-backed repository provide useful context for adoption. Licensing is not recognized in package metadata or license files, and the project has no security policy or automated security scanning.
43%
Total Score
50
100
72
75
The latest release was published in July 2018, with no releases in the last 12 months and only two releases over roughly 12 years. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance activity.
No declared license, recognized license text, or license file was detected in the collected package or repository. The README mentions GPL V2, but the signal does not recognize that as a license declaration or file.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a dormant project, though it does not independently prove abandonment.
The repository has zero stars and one fork, so there is little public adoption evidence. Popularity is supporting evidence rather than a decisive health measure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
papaya/cms-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.