The package is clearly documented, licensed, stable, and recently updated. Its small contributor base and workflow hygiene leave some maintenance and release-process risk.
76%
Total Score
75
100
94
75
The repository is owned by an individual rather than an organization, so the single-contributor concentration is not visibly offset by organizational maintenance capacity.
One contributor made all 27 recent commits, creating a meaningful continuity risk if that maintainer becomes unavailable.
The project uses a build tool, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so vulnerability reporting and handling expectations are not documented.
The only workflow gives top-level write permissions and all 3 action references are unpinned. The audit also reported a low-confidence cache-poisoning pattern; these are release-hygiene cautions, not evidence of a severe workflow compromise.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.