Risky to adopt: the last release was over 10 years ago and the repository has had no commits or active maintainers in the past three months. It is not deprecated or archived and has matching organization backing, but the long abandonment gap makes ongoing compatibility and support unlikely.
35%
Total Score
50
75
50
The latest release was published over 10 years ago, with no releases in the last 12 months. Eight releases were clustered early in the project’s life, but there is no recent evidence of maintenance.
The repository recorded 0 commits and 0 active maintainers in the last three months, consistent with the release history showing no release for over 10 years. This is strong evidence of abandonment risk.
The package runs a post-autoload-dump install-time script, which adds some installation complexity and execution surface. No provided signal shows that this script is unsafe, so this is a caution rather than a severe risk.
Composer is used as the build tool, but no security scanning tools are present. For this small, inactive package the missing scanning is a transparency gap, though it is less important than the lack of maintenance.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This lowers transparency, although the package’s dominant risk is its prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xinix-technology/blade-theme Version ~1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.