NexoPOS v6.2.3 appears to be a healthy, actively maintained release with a multi-year history, 120 releases, 12 releases in the last 12 months, and a latest release published very recently. The linked repository is active, unarchived, correctly associated with the package, includes tests, a security policy, dependency scanning, and workflows without the analyzed dangerous patterns. The main concerns are a highly concentrated contributor base—one contributor made about 90% of the last three months' commits—and several install-time lifecycle scripts, while the repository's workflows do not declare top-level token permissions. These warrant review for operational and continuity risk but do not outweigh the strong release and maintenance evidence.
82%
Total Score
75
50
100
80
The application declares 31 runtime dependencies and 6 development dependencies, a substantial profile that increases upgrade and transitive-risk surface. The breadth is also consistent with a full-featured POS/Laravel application, so this is a moderate caution rather than a severe health concern.
Five install- or update-time Composer lifecycle scripts execute during common package operations, increasing installation complexity and the amount of code that runs automatically. This is a caution for dependency review, although such scripts can be expected for a full Laravel application.
The repository is owned by a user account rather than an organization, so the concentrated contribution pattern is not visibly offset by organization-level maintenance backing.
Although four contributors were active, the top contributor produced about 90% of the last three months' commits, leaving meaningful continuity risk for a user-owned project.
Neither analyzed workflow declares top-level token permissions. While no top-level write permissions were detected, the absence of explicit permissions is a CI hardening gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
brick/math Version ^0.14.1 | — | — |
laravel/mcp Version ^0.7.2 | — | — |
doctrine/dbal Version ^3.0 | — | — |
dompdf/dompdf Version ^3.1 | — | — |
predis/predis Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.