It has a clear README, matching source repository, MIT licensing, and no install scripts. Its limited security tooling and small project footprint add modest maintenance exposure.
62%
Total Score
50
100
88
75
Only two releases are recorded, with the latest in November 2019 and none in the last 12 months. The release notes explain that this starter tag is intentionally updated only for major or minor Pico versions, which partly offsets the apparent inactivity.
No commits and no active maintainers were recorded in the last three months. The recent push timestamp is a compensating sign of repository availability, but it does not demonstrate ongoing development.
Composer is used for the build, but no security scanning tools are configured. That is a modest repository-hygiene gap, not evidence that the release is unsafe.
The repository has no security policy. For a starter package this is a transparency gap, although it is less significant than it would be for security-sensitive code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
picocms/pico Version ^2.1 | — | — |
picocms/pico-theme Version ^2.1 | — | — |
picocms/pico-deprecated Version ^2.1 | — | — |
picocms/composer-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.