Some new component
62%
Total Score
88
71
67
The package runs post-install and post-update Composer scripts, which expand install-time behavior and deserve extra trust in the publishing project.
The package has only one release, published over 11 years ago, with no releases in the last 12 months. This weakens confidence in the registry release as a maintained dependency, despite recent repository activity.
The repository has 23 open issues and no issues closed in the last month, although one pull request was merged. This suggests unresolved maintenance work but not clear abandonment.
The repository name does not exactly match the package name and its README does not mention the package, leaving some uncertainty that the linked source is the intended project. The shared organization and Docker Bundle content provide partial context but do not remove that gap.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a hygiene weakness rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ~2.6.16 | — | — |
syrup/component-bundle Version ~1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.