The package is clearly identified, properly licensed, and documented for consumers. Its static template format makes missing tests less concerning, but the lack of security tooling leaves maintenance transparency thinner.
58%
Total Score
50
86
50
Only three releases have been published, with no release in roughly 3 years and 5 months and a median interval of about 3 years and 7 months. The repository is not archived, but this still indicates very slow maintenance.
The repository recorded no commits and no active maintainers during the last 3 months, consistent with the last push occurring roughly 3 years and 5 months ago. This is the main abandonment concern despite the package being a small, stable template.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is a positive foundation, while the missing scanning is a modest hygiene concern.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a minor gap rather than a severe risk for a static front-end template.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.