Healthy and reasonable to use. It has a long release history, recent releases, clear licensing, matching source code, tests, and organizational backing; maintenance is active but recent repository work is limited to one contributor and there is no security policy.
82%
Total Score
67
100
89
90
All recent commits came from one contributor, creating concentration risk; the organization-owned repository provides some ability to hand maintenance off, so this is a caution rather than a severe risk.
There was one commit in the last 3 months from one active maintainer, which shows recent activity but is a thin maintenance pace and lowers confidence in sustained capacity.
The repository has no stars and only one fork, indicating limited visible adoption. This is supporting context rather than a health verdict because the package otherwise has sustained release history and recent activity.
Composer build tooling is present, but no security-scanning tool is reported. That is a transparency gap, though it is partly offset by the package's clear structure and active release history.
The repository has no security policy, leaving vulnerability-reporting and response practices undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
skeeks/cms-job Version ^1.0.6 || dev-master | — | — |
skeeks/cms-agent Version ^3.2.4 || dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.