Risky to adopt because the last release and repository activity were in February 2017, with no recent commits or active maintainers. It is licensed, has a matching repository with a usable README, and is not deprecated or archived, but the long abandonment period makes ongoing compatibility and support unlikely.
38%
Total Score
50
100
72
90
Only two releases exist, the latest on February 1, 2017, with no releases in the last 12 months. This long period without published updates is a meaningful abandonment and compatibility concern.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having been inactive since February 2017. This is the strongest evidence that ongoing fixes and compatibility work are unlikely.
There are no open issues or pull requests and no activity in the last month. While a clean tracker can be positive, here it provides no evidence of an engaged maintenance community.
The repository has 2 stars, 0 forks, and 1 watcher, offering little community evidence or independent adoption to compensate for the stale maintenance record.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a hygiene gap, though the package's much older and inactive state is the larger concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.