Clear documentation, a license, and a security policy make adoption easier. The maintainer base is narrow, but a second active contributor and 67 recent commits provide some continuity.
88%
Total Score
75
100
94
100
Commit activity is highly concentrated: one contributor made about 97% of the 67 recent commits. A second active contributor provides some continuity, but the maintainer base remains narrow.
Composer build tooling is present, but no repository security-scanning tool was detected; the separate security policy and clean workflow audit partly compensate for that gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-4267 johnbillion/query-monitor is vulnerable to Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in versions 0.0.0 - 3.20.4. | 0.0.0 - 3.20.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.