Usable with caveats: it has a real, tested repository, organizational backing, and no deprecation or archived status. However, the last release was about 20 months ago, repository work stopped about 19 months ago, and the package declares a proprietary license.
62%
Total Score
75
81
67
The manifest declares a proprietary license, so the release is licensed, but that creates compatibility and redistribution concerns for a package presented as open source. No license file provides additional terms or clarification.
The package has six releases since August 2019, but no releases in the last 12 months and its latest release was published in January 2025. This indicates materially reduced maintenance activity for a dependency consumers may need to keep compatible.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with roughly 19 months since its last push. This is a meaningful maintenance and compatibility risk.
The repository uses Composer for builds, providing basic build structure, but it has no security scanning tools. That is a modest transparency and hygiene gap, not evidence that the package is unsafe by itself.
No security policy was found in the repository, leaving vulnerability reporting and response expectations undocumented. This lowers transparency for a package intended to be used as a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pumukit/pumukit Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.