Clear documentation, release notes, and a small dependency footprint support adoption. Maintenance is concentrated in one person, while workflow pinning and security-policy gaps add modest operational risk.
78%
Total Score
88
100
94
75
One contributor made all 24 commits in the last three months, so continuity depends heavily on a single person. The directly matching repository and active release history provide some compensation, but not full redundancy.
Composer build tooling is present, but no security-scanning tooling was detected. For a plugin handling password protection, that is a modest transparency and maintenance gap.
The repository has no security policy. This is a modest gap for a package that handles authentication-related behavior, though active maintenance and release notes provide some compensating evidence.
The only workflow was fully analyzed with no untrusted checkout or script-injection path, but all three action references are unpinned and the workflow uses top-level write permissions. The low-confidence cache-poisoning finding is hygiene rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.