The linked project remains maintained, licensed, and backed by an organization, with recent commits and release notes. Use matomo/searchengine-and-social-list instead of this abandoned package.
22%
Total Score
100
70
50
Packagist marks the package abandoned at package scope and explicitly names matomo/searchengine-and-social-list as its replacement. This is a severe dependency-health risk despite other positive project evidence.
The package has 25 releases since 2015, but its latest registry release was about 3 years and 3 months before collection, with no releases in the last 12 months. Recent repository activity partly offsets the registry staleness but does not restore this package's release flow.
The linked repository has no published security policy. This is a transparency gap, though it is secondary to the package's abandonment status.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both action references are unpinned. The missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.