The package has a license, tests, a README, and organization backing, which support basic transparency. Its security policy is absent, and the source project shows no recent maintenance, so pinning this release carries substantial abandonment risk.
38%
Total Score
50
75
75
Only two releases exist, both last published about 10 years ago, with none in the past 12 months. This is strong evidence of abandonment despite the stable 1.1 version.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap and materially increasing maintenance risk.
The repository name does not match the package name and its README does not mention the package, so the source-to-package relationship is not clearly demonstrated.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is secondary to the much stronger abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ezsystems/ezpublish-legacy-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.