The MIT license, matching repository, and single runtime dependency make adoption straightforward. There has been no maintenance or release activity since January 2018, and the repository has no security scanning.
42%
Total Score
50
100
71
75
This package has only one release, 0.1.0, published about 8 years ago, with no releases in the last 12 months; that is strong evidence of abandonment risk.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the repository having been inactive since January 2018.
Composer is used for builds, but no security scanning tools are present. This is a maintenance and supply-chain hygiene gap, especially for a package with no recent development activity.
The repository has no security policy, leaving vulnerability reporting and handling undocumented. This adds a transparency gap, though it is less serious than the prolonged inactivity.
The latest version is 0.1.0 and is not a stable major release, which provides little evidence of a mature, settled API. Its long period without subsequent releases reinforces that concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/flow Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.