CMS Core admin module
58%
Total Score
caution
Usable with caveats: maintenance has stalled, with no commits in the last three months and no releases in the last year.
The artifact contains license files for bundled BSD-3-Clause, Apache-2.0, and LGPL-2.1 components, but the manifest declares the package proprietary, creating a material licensing-clarity concern.
Only one registry account can publish the package, which leaves little publishing redundancy; the linked repository is user-owned rather than organization-backed.
The package has only three releases and none in the last 12 months; the 284-day median interval indicates slow maintenance, though it is not complete abandonment.
There were no commits and no active maintainers in the last three months, a strong sign that maintenance has currently stalled.
The repository name matches the package, but the package name was not found in its README; the README instead describes elFinder, leaving package identity and provenance unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 1.35.0 | — | — |
twig/extensions Version ^1.3 | — | — |
rcrowe/twigbridge Version ^0.9.2 | — | — |
intervention/image Version ^2.3 | — | — |
cviebrock/image-validator Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.