The source is compact and has clear installation instructions. Regular releases and organizational ownership offset limited recent commit activity, but the proprietary license and absent security policy warrant checking before adoption.
64%
Total Score
75
100
81
50
The manifest declares a proprietary license, but no license file was detected in the package or repository. This creates a material licensing and transparency concern for downstream users.
There were no commits or active maintainers in the last 3 months. The recent registry releases and repository push provide some compensating evidence, but the current maintenance activity is still thin.
Composer is used for builds, but no security-scanning tools are present. For a small module this is a hygiene gap rather than evidence of abandonment.
The repository has no security policy. This reduces transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
blesta/composer-installer Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.