Healthy and actively maintained, with a strong release cadence and clear repository backing. The main caveats are that recent work is concentrated in one contributor and the repository lacks a security policy while its release workflow has write access.
82%
Total Score
83
50
94
75
Seven runtime dependencies, including multiple AI provider SDKs and utility packages, create meaningful update and compatibility surface, but the profile is still understandable for an AI integration plugin.
All 147 recent commits came from one contributor, leaving a thin operational fallback if that person becomes unavailable.
The repository uses Composer build tooling, but no security-scanning tools were detected; the build setup is present while automated security coverage is limited.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear for a package that integrates several external AI services.
The release workflow declares top-level write permissions, which expands the potential impact of a compromised workflow even though dangerous workflow patterns were not detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
anthropic-ai/sdk Version ^0.17 | — | — |
guzzlehttp/guzzle Version ^7.10 | — | — |
openai-php/client Version ^0.19 | — | — |
getkirby/composer-installer Version ^1 | — | — |
johannschopplich/kirby-tools-utils Version ^0.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.