The organization backing helps provide handoff capacity, while the project uses Composer and Dependabot. The single active contributor and four unpinned workflow actions leave meaningful maintenance and build-integrity caveats.
68%
Total Score
75
100
100
67
One contributor made 100% of the recent commits. Organization ownership provides some handoff capacity, but the observed maintenance base is still narrow.
Seven commits were made in the last three months by one active maintainer, which shows recent work but also leaves maintenance capacity concentrated.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent for users.
The only workflow was fully analyzed with no high-confidence findings or unsafe triggers, but all four action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.