It has a clear MIT license, release notes for this version, and no install-time scripts. Security scanning is absent and all recent commits came from one contributor, so continuity depends heavily on that maintainer.
78%
Total Score
67
94
75
The repository is owned by an individual rather than an organization, so the one-contributor concentration is not offset by visible organizational backing.
All 26 recent commits came from one contributor, creating a meaningful continuity risk despite the package having two registry maintainers.
Composer is used for builds, but no security scanning tools are configured, leaving a maintenance and transparency gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
whichbrowser/parser Version ^2.1 | — | — |
simplestats/referer-parser Version ^1.1 | — | — |
getkirby/composer-installer Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.