The package is licensed, releases are frequent, and the repository was updated recently. Two active contributors and organizational backing help offset concentrated commit activity, while missing security tooling and an unpinned workflow leave modest gaps.
82%
Total Score
83
100
86
67
One contributor made about 79% of the 24 recent commits, creating concentration risk, although a second contributor made five commits and the repository is organization-owned.
The repository has no stars or forks and seven watchers, offering little external adoption evidence; this is only supporting context because recent releases and commits demonstrate activity.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance-hygiene gap.
The repository has no security policy, so users lack a documented channel or process for reporting vulnerabilities.
The sole workflow was fully analyzed with no audit findings or untrusted checkout and script-injection sinks. However, its one action reference is unpinned, so the workflow has a small supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elasticms/core-bundle Version 7.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.