The MIT license, focused README, and organization-owned repository provide useful transparency. The lack of security tooling and security policy adds maintenance risk for a security-focused package.
40%
Total Score
50
79
83
The latest release was over 7 years ago, with no releases in the last 12 months. Fifteen releases show some history, but the long inactive period materially raises abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance capacity.
Composer build tooling is present, but no security-scanning tools were detected. That is a meaningful hygiene gap for a security-focused package.
The repository has no security policy. For a package explicitly providing CMS security widgets, this weakens vulnerability-reporting transparency and maintenance confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ride/app Version ^1.0.0 | — | — |
ride/web Version ^1.0.0 | — | — |
ride/lib-cms Version ^1.0.0 | — | — |
ride/web-cms Version ^1.0.0 | — | — |
ride/lib-form Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.