There has been no registry release or repository commit since November 2020, and the project has no security policy or scanning tooling. The MIT license, README, and small dependency surface improve transparency, but they do not offset the abandonment risk.
38%
Total Score
25
100
78
83
This is a five-year-old package with only one release and no releases in the last 12 months, which is strong evidence of abandonment for a dependency.
There were no commits and no active maintainers in the last three months, consistent with the package's long release gap and materially increasing abandonment risk.
The repository is owned by an individual rather than an organization, and no organizational backing is shown. This makes the absence of recent activity more concerning than it would be for an actively maintained organization-owned project.
Zero stars and forks and only one watcher indicate little visible community adoption or support, adding to the uncertainty around a dormant project.
Composer build tooling is present, but no security scanning tools were detected. This is a maintenance and transparency gap, though not evidence of a specific security issue.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/flow Version ^5.0 | — | — |
neos/event-sourcing Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.