A Composer plugin for platform-aware distribution URL resolution
68%
Total Score
50
100
94
83
The repository recorded 0 commits and 0 active maintainers in the past 3 months. Although the latest release was recent, this short-term inactivity is a real maintenance concern.
Composer build tooling is present, but no security-scanning tool is configured. For a plugin that participates in package installation, that missing automated security check modestly reduces transparency.
The repository has no security policy. This does not show a vulnerability, but it leaves no documented channel or process for handling security reports.
The single workflow was fully analyzed with no high-confidence audit findings or dangerous triggers, but all 3 action references are unpinned. That leaves build behavior exposed to upstream action changes despite otherwise clean workflow results.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.