Clear licensing and usable documentation make integration easier. The small dependency set and matching source repository add transparency, while absent security tooling leaves a modest process gap.
56%
Total Score
50
100
67
50
Only two releases exist, with the latest in June 2022 and none in the last 12 months. That long release gap raises maintenance and abandonment concerns despite the repository being updated more recently.
The repository recorded no commits and no active maintainers in the last 3 months. Although it is not archived and was pushed in March 2025, current development activity is weak.
Composer is used for the build, providing ordinary ecosystem tooling. No security scanning tools were detected, which is a modest repository-process weakness but not evidence of an unsafe release by itself.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, but it is less severe than evidence of abandoned or archived source.
Version 0.0.2 is not a stable major release, so compatibility expectations are limited. It is not marked as a prerelease, which partly offsets the risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.4 | — | — |
symfony/event-dispatcher Version ^4.4.0 | — | — |
openemr/oe-module-installer-plugin Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.