The organization-backed repository, clear README, and single runtime dependency make the plugin straightforward to evaluate and integrate. Confirm the licensing terms and expect slower maintenance because recent repository activity is limited.
61%
Total Score
75
100
79
50
The manifest declares a proprietary license, while the artifact and repository contain an MIT license file. That mismatch creates real uncertainty about the terms under which this release may be used.
The package has three releases over about 13 months, with one release in the last 12 months and a median interval of about 126 days. This indicates a relatively slow release cadence, though it is not evidence of abandonment by itself.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push and organization backing partly offset this, but the lack of observed development activity still raises maintenance risk.
Composer is used as a build tool, but no security-scanning tools were detected. The missing scanning is a transparency and maintenance weakness, not a standalone reason to reject the package.
The repository has no security policy. This weakens the project's documented process for handling security reports, although it does not by itself show that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
blesta/composer-installer Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.