Recent commits, releases, tests, and documentation support ongoing project work. Concentrated authorship and broad runtime dependencies add adoption risk.
38%
Total Score
83
50
81
50
Packagist marks the package abandoned at package scope and names ec-europa/toolkit as its replacement. This is a major adoption and continuity concern despite evidence that the underlying project remains active.
The package declares 27 runtime dependencies, including testing, static-analysis, coding-standard, and development tooling. That broad runtime profile increases integration and transitive-maintenance burden for consumers.
The package runs post-install and post-update Composer scripts. These scripts expand installation-time behavior and warrant caution for a dependency, although this signal alone does not establish severe risk.
One contributor made 87.5% of the recent commits, while two others made one each. The organization-owned project provides some handoff capacity, but recent work is still highly concentrated.
The repository name does not match the package name and its README does not mention ec-europa/ssk. Although a name mismatch can be normal for a sub-package, the missing README reference makes package-to-repository identity less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3.7 | — | — |
drush/drush Version ^11.0.4 || ^12.0 || ^13.0 | — | — |
phpmd/phpmd Version ^2.12 | — | — |
drupal/coder Version ^8.3.10 || ^9.0 | — | — |
phpstan/phpstan Version ^1.12.15 || ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.