The package is small and focused, with a stable 1.0.1 release and one runtime dependency. Its organization-backed repository and README reference provide useful provenance; check compatibility with your papaya CMS version before adoption.
43%
Total Score
50
100
71
75
The package has only two releases, with the latest published in January 2017 and none in the last 12 months. This is strong evidence of abandonment risk for a dependency that may need compatibility or security maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push occurring in January 2017. No newer activity compensates for this maintenance gap.
No declared license, recognized license file, or repository license file was detected. Although the README mentions GPL v2, the collected license metadata does not establish a machine-readable or file-based license for the package.
The repository uses Composer for its build workflow, but no security scanning tools were detected. The missing scanning is a modest hygiene concern, not a standalone reason to reject the package.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a secondary transparency gap alongside the absence of recent maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
papaya/cms-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.