Usable with caveats. It has frequent stable releases, an active organization-backed repository, and a current release, but no recorded commits or active maintainers in the last three months, no tests, and limited security-process evidence.
72%
Total Score
75
100
83
80
Composer post-install and post-update scripts run during dependency operations. These add operational risk and deserve review before adoption, although the signal does not by itself indicate abandonment.
The artifact and repository include a README and changelog, but neither contains tests. For a backoffice UI bundle, absent tests reduce maintenance confidence because no provided signal compensates for that gap.
The repository recorded zero commits and zero active maintainers in the last three months, which is a real maintenance-capacity concern. Frequent recent releases and a current push partly compensate, so this is not evidence that the package is abandoned outright.
There were no new or merged issues or pull requests in the last month, with one open pull request. This suggests limited visible collaboration, though the open-issue count is unavailable and the package is releasing frequently.
The repository has zero stars and forks and only two watchers. This is weak supporting evidence, but popularity is not decisive and the package has strong release activity and organization backing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
roadiz/openid Version 2.7.* | — | — |
deeplcom/deepl-php Version ^1.12 | — | — |
roadiz/core-bundle Version 2.7.* | — | — |
roadiz/doc-generator Version 2.7.* | — | — |
roadiz/dts-generator Version 2.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.