Its small, focused artifact has a modest dependency surface and no install-time scripts. Organization ownership and a matching repository improve traceability, but this release should be treated as legacy software.
35%
Total Score
67
100
67
83
The latest release was published more than 10 years ago, with no releases in the last 12 months. That long lapse is strong evidence of abandonment risk despite a history of nine releases.
There were no commits or active maintainers in the last three months, and the repository was last pushed nearly 10 years ago. This is a substantial abandonment risk.
The package has no README, while tests and a changelog are absent from the artifact and repository; the latter two are normal for published packages. Missing consumer documentation is a minor transparency concern for a backend add-on.
The repository has zero stars and one fork, providing little supporting evidence of adoption or an active user community. Popularity is only supporting evidence, so this is a modest concern.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling was detected. The missing scanning is a hygiene gap rather than a standalone reason to reject the release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sallycms/sallycms Version >=0.10,<0.11 | — | — |
sallycms/composer-installer Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.