The clear MIT license, matching repository, and simple dependency profile improve transparency. The project has little supporting security or community evidence, so future maintenance may be difficult.
45%
Total Score
100
63
75
This is the package's only release, published about nine years ago, with no releases in the last 12 months. That strongly suggests abandonment risk.
The repository has zero stars and forks and only three watchers. Popularity is not decisive, but these figures provide little evidence of active community use or support.
Composer is used for builds, but no security-scanning tooling is reported. This is a modest transparency and maintenance gap rather than a severe risk by itself.
The repository is not archived, but it was last pushed about eight years ago. The unarchived status is reassuring, while the long inactivity remains a maintenance concern.
No security policy is present in the repository, leaving vulnerability reporting expectations unclear. This adds a small transparency concern for a package that manages application page content.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.