Usable with caveats: this is a young but actively released package with tests, clear documentation, and a current source repository. Dependence on one contributor, no security policy, and no repository security scanning increase maintenance and transparency risk.
72%
Total Score
67
100
83
88
The package is only 66 days old but has 17 releases, including releases within the last 12 months and a median interval of about 1.3 days. This shows strong recent activity, though the short history leaves long-term maturity unproven.
One contributor made 100% of the 21 recent commits. Organization backing provides some continuity, but no second active contributor is shown, so maintainer loss remains a real risk.
There were 21 commits in the last three months, all from one active maintainer, showing recent maintenance but limited evidence of a broader maintenance base.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of community visibility leaves little external evidence of adoption or review.
Composer is used as a build tool, but no security scanning tools are configured. This is a transparency and maintenance gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
skeeks/cms Version ^6.4.9.27 || dev-master | — | — |
skeeks/cms-oauth2-server Version ^1.0 || dev-main || dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.