Fastly integration for BEAR.Sunday
67%
Total Score
63
100
89
75
The package uses post-install and post-update Composer scripts, which add install-time execution risk and warrant review even though no other signal indicates malicious behavior.
Only one registry account has publishing access, which is a limited release-side safety net. The organization backing shown by the repository makes this less concerning than a single-person project, but it still leaves little registry redundancy.
No commits or active maintainers were recorded during the last three months. This is the clearest maintenance concern, although the repository was pushed within the broader recent period and the package had two releases in the last year.
There are no open issues and two open pull requests, with no issues or pull requests newly created or merged in the last month. The lack of current issue activity is not itself abandonment, but the unmerged pull requests add a small maintenance concern.
The repository name differs from the registry package name and its README does not mention bear/fastly-module. The naming difference could be normal for this repository, but the missing README reference makes package ownership and correspondence less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ray/di Version ^2.13.1 | — | — |
fastly/fastly Version ^11.0 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.