The repository is active, and the package includes tests, a clear license, and a matching source repository. Workflow references are not pinned, and the project has no security policy or automated security scanning, leaving avoidable maintenance gaps.
68%
Total Score
83
50
88
50
The package declares 20 runtime dependencies, including several related project packages. This is a meaningful dependency surface but is coherent for a substantial Icinga Web module.
A post-update-cmd lifecycle script runs during dependency updates. This adds installation-time behavior that should be understood, though the signal alone does not show harmful activity.
All 32 recent commits came from one contributor, creating a concentrated maintenance dependency. The organization-owned repository partly compensates by providing a broader project home, but no second active contributor is shown.
Composer is used as a build tool, but no security scanning tools are detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
imedge/svg Version >=0.2.1 | — | — |
imedge/web-rpc Version >=0.4 | — | — |
imedge/rrdgraph Version >=0.5 | — | — |
imedge/web-data Version >=0.14 | — | — |
imedge/web-flags Version >=0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.