The repository includes tests, a changelog, matching package references, and a clear MIT license. Its small maintainer base and limited workflow pinning leave less maintenance and build-integrity margin than a mature dependency.
61%
Total Score
50
100
88
75
Only one registry publishing maintainer is listed, and the repository is owned by the same individual rather than an organization. This leaves limited visible publishing and maintenance redundancy.
The repository owner is an individual rather than an organization, so there is no demonstrated organizational backing to compensate for the one-person maintainer base.
The package has four releases, all concentrated within about 9 days, followed by roughly 10 months without a release. That short history and long quiet period raise abandonment concerns.
There were no commits and no active maintainers in the last 3 months. Combined with the release history, this indicates that maintenance has currently stalled.
The repository uses Composer for builds, but no security-scanning tools are reported. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.