Documentation, licensing, and a release note are solid, and the package has no install-time scripts. Its last release was over six years ago, with no recent commits, and the repository does not clearly identify the package in its name or README.
62%
Total Score
50
100
75
83
The package has only three releases and no release in the last six years, indicating a long period without demonstrated maintenance. Its age and stable release history provide some maturity, but do not offset the prolonged inactivity.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and suggesting little current maintenance capacity.
The repository name does not match the package name and its README does not mention the package, so the source relationship is not clearly established by the collected metadata. The matching owner and focused file tree provide some context, but do not remove that transparency concern.
The repository uses Composer for builds, but no security scanning tools were detected. For this small package the missing scanner is a hygiene gap, not evidence of abandonment by itself.
The linked repository is not archived, but it was last pushed more than four years ago. Its available status is better than an archived project, while the old push date still supports the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
processwire/processwire Version >=3.0.0 | — | — |
wireframe-framework/processwire-composer-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.