Documentation is unusually complete for a first release, and the license and package contents are clear. The project has no established maintenance record, tests, security policy, or security scanning, so pin this version only if you can accept early-project risk.
62%
Total Score
50
100
75
75
This package was released today and has only one release, so there is no track record for maintenance or release reliability yet.
There were no commits or active maintainers during the last three months. Because the repository and package were created today, this is consistent with a new project but still provides no evidence of sustained maintenance.
Composer is used as the build tool, but no security scanning tool is configured, leaving automated detection of dependency or source issues weaker than it could be.
The repository has no security policy, so users are given no documented process for reporting vulnerabilities or receiving security fixes.
Version 0.1 is an early initial release rather than a stable major version, which increases compatibility uncertainty for adopters.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.