The package has tests, a changelog, a usable README, and eight releases in the last year. No security policy or security scanning is present, which weakens transparency despite the otherwise clear project structure.
68%
Total Score
50
100
93
50
Only one registry account has publishing access. The linked repository is user-owned rather than organization-backed, so the release has a thin apparent maintainer base.
The source repository is owned by an individual account rather than an organization, providing less visible institutional backing for long-term maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance warning despite the recent registry releases.
Composer build tooling is present, but no security-scanning tools were detected, leaving automated security coverage unclear.
The repository has no security policy, so there is no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elgg/elgg Version ~7.0.0 | — | — |
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.