The repository has tests, release notes, security scanning, and a security policy. Workflow checks need attention, and the package-to-repository naming mismatch reduces transparency; the recent work is concentrated in one maintainer.
62%
Total Score
70
100
94
67
Post-install and post-update scripts run during Composer operations, adding execution surface for consumers. No provided signal shows these scripts are unsafe, so this is a limited supply-chain concern rather than a severe risk.
The source repository is owned by a user rather than an organization, so the concentrated recent contribution profile is not offset by clear organizational handoff capacity.
All recent commits come from one contributor with a 100% share, creating a meaningful continuity risk for a user-owned project.
Only 2 commits were made in the last 3 months, with one active maintainer, so current maintenance activity is thin despite frequent registry releases.
The repository name does not match the package name and its README does not mention the package, making the package-to-source relationship less transparent even though the repository appears related by owner and content.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wikimedia/composer-merge-plugin Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.