The detailed README, matching repository, MIT declaration, and lack of install-time scripts make the package transparent to inspect. Its single-star repository and missing security policy provide little additional assurance for future maintenance.
35%
Total Score
50
100
72
75
The latest release was published in October 2018, with no releases in the last 12 months despite a package age of about 8 years. This strongly indicates abandonment risk, although the registry does not mark the package deprecated.
There were zero commits and zero active maintainers in the last 3 months, consistent with the last push occurring in October 2018. This is strong evidence that maintenance has stopped.
The repository has 1 star and no forks, so there is little public evidence of broad adoption or community support. Popularity is only supporting evidence, so this remains a moderate concern.
Composer is used as the build tool, but no security scanning tools are configured. That weakens repository hygiene, though it is secondary to the much larger maintenance concern.
The repository has no security policy. This reduces transparency about vulnerability reporting and response, especially for an extension that handles deployment and credential-related operations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimcore/core-version Version >=5.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.