Its release notes, README, and matching repository make the package easy to understand. The long silence in releases and commits, plus the license mismatch and absent security policy, leave it a poor choice for new dependencies.
38%
Total Score
50
75
75
The package has had no releases in the last 12 months, and its latest release was in February 2017. That long period without published maintenance is a substantial abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, confirming that the project is not currently maintained.
The artifact declares a proprietary license but contains a BSD-3-Clause license file, creating a material licensing inconsistency despite the presence of license files.
The repository uses Composer build tooling, but it has no security scanning tools. Given the project's age and inactivity, the missing scanning is a minor transparency weakness.
The linked repository has no security policy. For a package that ships a browser editor and many JavaScript assets, this weakens vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.