The organization-backed project includes tests, a substantial README, and release notes for this version. Limited recent development, no security policy, and unpinned workflow actions leave meaningful maintenance and build-integrity concerns.
65%
Total Score
67
100
88
75
The package declares GPL-3.0+ and includes both artifact and repository license files, so licensing is transparent; the detected GPL-3.0 text is narrower than the declaration and merits a small clarification.
There were zero commits and zero active maintainers during the last three months. Although the release was published recently, the lack of observed development reduces confidence in ongoing maintenance.
The repository has seven open issues and two open pull requests, with one new issue but no issues or pull requests closed in the last month. This suggests limited issue throughput, though it is not conclusive abandonment evidence.
Composer is used for builds, but no security-scanning tool was detected. This is a modest transparency and assurance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or communicating security practices.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos Version ^9.0 | — | — |
neos/fusion Version ^9.0 | — | — |
neos/fusion-form Version ~3.0 || dev-main | — | — |
neos/symfonymailer Version ^0.1 || ^1.0 | — | — |
sitegeist/inspectorgadget Version ^v3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.