Healthy and actively maintained, with clear source alignment and frequent releases. The main caveat is that all recent commits come from one contributor, while the repository lacks security scanning and a security policy.
82%
Total Score
90
100
94
80
One contributor made all 149 commits in the last 3 months, creating a genuine continuity risk. Organization backing partly compensates because maintenance can potentially be handed off internally.
Composer is used for builds, but no security scanning tools are configured, leaving a modest transparency and detection gap.
The repository has no security policy, which leaves vulnerability-reporting expectations unclear for a package intended for production CMS installations.
The release workflow declares top-level write permissions. This is broader workflow access than read-only permissions and increases release automation exposure, though no dangerous workflow pattern was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1 | — | — |
johannschopplich/kirby-tools-utils Version ^0.1 | — | — |
johannschopplich/kirby-tools-licensing Version ^0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.