This release appears usable and reasonably supported by an organization-owned repository, a non-deprecated stable version, recent release activity, and a small dependency surface. However, maintenance evidence is mixed: the repository had no commits or active maintainers in the last 3 months, while the package provides no tests or changelog and has no security policy or security-scanning tooling. The package is not an obvious abandonment risk because it was released recently and has recent pull-request merges, but these transparency and maintenance gaps warrant caution before adopting it as a critical dependency.
68%
Total Score
88
100
83
90
A README is present, but the artifact and repository have no tests or changelog. For a module with integration-facing behavior, the lack of visible verification and change documentation lowers transparency.
The repository recorded 0 commits and 0 active maintainers during the last 3 months. This is a meaningful maintenance concern, although it is partly offset by the recent release and recent merged pull requests.
The repository has 0 stars, 1 fork, and 3 watchers, showing limited external adoption or review. Popularity is supporting evidence rather than decisive, but this provides little independent validation.
Composer is used as a build tool, but no security-scanning tools are configured. The build setup is appropriate for the package ecosystem, while the missing security automation is a transparency and assurance gap.
The repository has no security policy. For a package that integrates with registrar APIs and manages domain-related operations, the missing vulnerability-reporting guidance is a genuine security transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
blesta/composer-installer Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.