The package is clearly identified, MIT-licensed, documented, and has a small dependency footprint. Its source remains available and unarchived, but maintenance activity has stopped, so compatibility with newer Cockpit CMS environments may require verification.
58%
Total Score
67
100
88
83
The package and repository are owned by the same individual account, giving clear ownership context. It also means there is no organization backing shown to provide additional maintenance capacity.
Only two releases have been published, with no release in more than three years and a median interval of about 853 days. This is a substantial maintenance concern for a package tied to a CMS, though the repository is still available and unarchived.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this indicates likely abandonment or at least very slow maintenance.
The repository uses Composer, matching the package ecosystem, but has no security scanning tools. For this small addon this is a hygiene gap rather than a severe dependency-health problem.
No repository security policy is present. This reduces transparency for reporting vulnerabilities, but it is a modest concern for a small, inactive addon rather than evidence that the release is unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.