The package is small and clearly packaged, with a README, changelog, and no install-time scripts. Its single-maintainer project has no tests or security policy, leaving limited evidence for long-term support.
70%
Total Score
50
100
86
75
Only one registry account can publish the package. That is a limited publishing base, though this signal alone does not establish whether the project is actively maintained.
The package has four releases since February 2023, with one release in the last 12 months and a median interval of about 383 days. The June 2026 release shows it is not abandoned, but the slow cadence limits maintenance confidence.
The repository recorded zero commits and zero active maintainers in the last three months. The recent release partly offsets this, but the current lack of observed development activity weakens maintenance confidence.
Composer is used as a build tool, but no security scanning tools were detected. For a small plugin this is a modest transparency gap rather than a severe risk.
The repository has no security policy. This reduces transparency about vulnerability reporting and handling, although the package's small scope limits the severity of the gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.