The repository includes tests and matches the package, but maintenance is concentrated in one contributor. Its workflow shows no dangerous patterns, although there is no security policy and registry publication is stale.
67%
Total Score
67
79
80
Only one release exists, and the latest was published about 3 years 11 months ago with none in the past year. Recent repository activity partly offsets the stale registry history, but release maturity remains limited.
One contributor made all three recent commits, concentrating maintenance in a single person. Organization ownership provides some handoff capacity, but no second active contributor is evidenced.
Three commits were made in the past 3 months, but activity comes from only one active maintainer. This supports ongoing attention while leaving limited maintenance depth.
Composer is used as a build tool, but no security scanning tool was detected. The build setup is present, while security transparency is limited.
The repository has no security policy. This is a transparency gap, though it is less serious for a small library with no dangerous workflow patterns detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
civicrm/composer-downloads-plugin Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.