The repository has had no commits for about seven years, and it has almost no community activity or security process. Documentation, licensing, and organizational backing help, but this old one-release project carries substantial maintenance risk.
42%
Total Score
50
100
63
80
This is the package's only release, published about seven years ago, with no releases in the last 12 months. That is strong evidence of an unmaintained dependency.
There were zero commits and zero active maintainers in the last three months, despite the repository being about seven years old. This is the strongest direct indication that fixes and updates may not arrive.
Composer runs post-create, post-install, and post-update scripts. These are plausible for an application template, but they increase installation behavior that consumers must trust.
One registry publishing account is listed, which is a thin operational base. The repository's organization backing partly offsets this concern, but does not demonstrate active maintenance.
There are no open issues or pull requests and no activity in the last month. This is consistent with a dormant project, though it does not by itself prove unresolved maintenance problems.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
skeeks/cms-basic Version ^1.0.0 | — | — |
skeeks/cms-theme-unify-v2 Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.