The package is licensed, tested, and has a long, steady release history. Workflow references are unpinned, and the repository lacks dedicated security scanning and a security policy.
78%
Total Score
67
100
94
50
A post-autoload-dump install-time script runs during Composer operations, adding execution complexity and a modest supply-chain exposure compared with a package without lifecycle scripts.
One contributor made all two recent commits, concentrating near-term maintenance capacity despite the organization-owned repository.
Only two commits were recorded in the last three months, so recent development activity is present but limited.
Composer build tooling is present, but no security-scanning tools were detected, leaving security hygiene less visible.
The repository has no published security policy, which weakens the documented process for reporting and handling vulnerabilities.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-15363 aoe/restler is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 1.7.1. | 0.0.0 - 1.7.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 | — | — |
luracast/restler Version ^5.0 | — | — |
cweagans/composer-patches Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.