The repository has no security scanning or security policy, which limits independent review. Organization backing, a recent push, frequent releases, and an explicit license provide useful support despite the thin public track record.
66%
Total Score
75
100
79
75
The package includes a README, while missing tests and a changelog are normal for published artifacts and are not health gaps here. The README is very short at 22 characters, limiting consumer documentation.
No commits and no active maintainers were recorded during the last three months. Although the repository was recently pushed and releases are frequent, the lack of observed development activity weakens confidence in ongoing maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this modestly reduces external validation but does not outweigh the active release history.
Composer is used as a build tool, showing basic project tooling, but no security scanning tools were detected. That leaves less automated coverage for dependency and code risks.
The repository has no security policy. This is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.