The organization-backed project includes tests, a usable README, and a clear license, with no install scripts or deprecation notice. Its single release, 0.1.0 version, absent commits for three months, missing security policy, and unpinned workflow actions leave maintenance and build-transparency concerns.
61%
Total Score
75
81
75
The package is about six months old but has only one release, so its maintenance history and long-term stability are not yet established.
The repository had no commits and no active maintainers during the last three months, a meaningful warning for a package with only one release.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest security-process gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
Version 0.1.0 is an early, non-stable-major release, which indicates a higher likelihood of API or behavior changes than a mature stable release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
civicrm/civicrm-core Version >=5.81 | — | — |
symfony/polyfill-php82 Version ^1.29 | — | — |
civicrm/civicrm-packages Version >=5.81 | — | — |
project60/org.project60.sepa Version dev-master | — | — |
systopia/civicrm-test-fixtures Version dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.