The MIT declaration, focused dependency list, and README make its intended integration clear. However, its last release and repository push were in October 2016, with no recent commits or security policy, leaving little evidence of current maintenance.
38%
Total Score
75
50
81
83
The package declares eight runtime dependencies and no development dependencies. The focused dependency set is understandable for a CMS integration, though its age makes compatibility with current dependency versions uncertain.
The package has had no releases in more than 9 years; its latest release was October 2016 and there were zero releases in the last 12 months. This is strong evidence of abandonment for a dependency that may need compatibility or security updates.
There were zero commits and zero active maintainers in the last three months. Combined with the last push being in 2016, this materially raises abandonment risk.
Composer is used as the build tool, providing basic ecosystem-appropriate packaging support. No security scanning tools were detected, leaving a modest repository hygiene gap.
The linked repository is not archived, which preserves a path for maintenance, but its last push was in October 2016 and therefore does not offset the inactivity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ride/app Version ^1.0.0 | — | — |
ride/web Version ^1.0.0 | — | — |
ride/lib-cms Version ^1.0.0 | — | — |
ride/web-cms Version ^1.0.0 | — | — |
ride/lib-i18n Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.