The package has a usable README and matching source repository, but its dependency declaration points back to itself and the repository has no security scanning or policy. Its small, single-user project has also shown no recent activity.
38%
Total Score
25
50
75
50
Only two releases exist, with the latest published in August 2017 and none in the last twelve months. This long release gap is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity for about nine years.
The only declared runtime dependency is the package itself, which is unusual and may indicate an erroneous or circular dependency declaration.
One registry maintainer provides limited publishing redundancy, and the project is user-owned rather than organization-backed. This increases the impact of the observed inactivity.
Composer is used as a build tool, which is appropriate, but no security scanning tools are configured. This is a modest transparency and maintenance gap, not a verdict by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zouxiang0639/form-builder Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.