Licensing, documentation, release notes, and a security policy are in place, with no install-time scripts. The project is organization-backed and correctly linked, but its recent activity is thin enough to warrant checking future maintenance before adopting.
69%
Total Score
83
88
100
The package has existed since October 2013 with 17 releases, but it has had no release in the last 12 months despite a latest release in August 2025. That recent pause lowers confidence in ongoing maintenance.
Only one commit was recorded in the last three months, from one active maintainer. This is thin recent maintenance evidence and raises the risk that fixes may be slow if activity stops.
Composer build tooling is present, but no security scanning tool was detected. That is a modest transparency gap rather than evidence of unsafe code.
The only workflow was fully analyzed with no injection or high-severity findings, but its sole action reference is unpinned. That is a minor reproducibility and dependency-hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
joomla/uri Version ^4.0 | — | — |
joomla/http Version ^4.0 | — | — |
joomla/input Version ^4.0 | — | — |
joomla/session Version ^4.0 | — | — |
joomla/registry Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.