The package is very new, with one release and only one recent commit, so its long-term maintenance is unproven. Organization backing, a clear README, licensing, dependency tooling, and Dependabot provide useful support; workflow references are all unpinned and no security policy is present.
68%
Total Score
67
100
93
67
The package is 47 days old and has only one release, so there is little evidence of sustained maintenance or release maturity.
All recent commits come from one contributor. The organization-owned repository provides some handoff capacity, but no second active contributor is evident.
One commit in the last three months shows recent activity, but the amount of activity is too small to establish a durable maintenance pattern.
The repository has no security policy, reducing the transparency of vulnerability reporting and response expectations.
The only workflow was fully analyzed with no dangerous audit findings and job-level permissions, but all 4 of 4 action references are unpinned, leaving build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.