The MIT declaration conflicts with the Apache-2.0 license found in the artifact. The README and exact-version release notes help consumers, but one release and no activity since 2020 leave maintenance unproven.
38%
Total Score
50
50
This package has only one release, published about 6 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a library dependency.
A license file is present, but the manifest declares MIT while the artifact license is recognized as Apache-2.0. The mismatch creates uncertainty about the terms applying to this release.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest hygiene gap and does not by itself establish a dependency risk.
The repository is not archived, but its last push was about 6 years ago, consistent with the package's single-release history and adding to the maintenance concern.
The repository has no security policy. This is a transparency gap for a package that handles an external search service, although it is less significant than the lack of ongoing releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elastic/app-search Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.