The organization-backed repository is intact and the release is clearly licensed, with no install-time scripts. However, there have been no commits or releases for about nine years, and the repository has no tests or security policy.
42%
Total Score
50
75
75
The package has had no release in about nine years, despite nine historical releases. This is strong evidence that maintenance has stopped rather than merely slowed.
There were zero commits and zero active maintainers during the last three months. Combined with the last push in 2017, this indicates a prolonged absence of active maintenance.
Composer is used as the build tool, but no security scanning tooling is present. That is a minor transparency and maintenance gap, not evidence that the release is unsafe by itself.
The repository is not marked archived, but its last push was in January 2017, so the unarchived status does not compensate for the stale activity.
The repository has no published security policy. For a package containing an admin theme, this weakens the project's documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.