Healthy and suitable to use, with a small maintenance risk. It has frequent recent releases, current repository activity, clear licensing, and complete package documentation; all recent commits come from one contributor and the repository has no security policy.
82%
Total Score
88
100
89
90
One contributor made all 6 commits in the last 3 months, creating a genuine continuity risk; the organization-owned repository provides some capacity to hand off maintenance, but no second active contributor is evidenced.
The repository has only 1 star and 2 forks, which offers little community validation or fallback support; this is a supporting concern rather than a decisive defect because release and commit activity are strong.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a transparency gap, although it is not evidence that the package is unsafe or unmaintained.
No security policy is present. This weakens the documented process for reporting and handling vulnerabilities, although the package has other evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
skeeks/cms-job Version ^1.0.6 || dev-master | — | — |
skeeks/cms-agent Version ^3.2.4 || dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.