Basic steps for a Nextcloud app
70%
Total Score
caution
Active releases and organization backing help, but one contributor and eight unpinned actions limit confidence.
The package runs post-install and post-update Composer scripts, which adds install-time behavior that consumers should understand, but this is not by itself a severe health concern.
Only one registry account has publishing access, which is a concentration risk, though the linked repository is organization-owned and active.
One contributor made all 5 commits in the last three months, creating a high individual concentration risk. Organization backing partly compensates because maintenance can potentially be handed off.
The repository has no security policy, which is a transparency gap for reporting vulnerabilities, although the package does use security scanning tools.
All 8 analyzed action references are unpinned, weakening build reproducibility and action supply-chain control. The audit found no dangerous triggers, sinks, or high-confidence workflow findings, and all workflows were analyzed successfully.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3.29 | — | — |
phpunit/phpunit Version * | — | — |
guzzlehttp/guzzle Version ^7.10 || ^8.0 | — | — |
estahn/json-query-wrapper Version * | — | — |
libresign/behat-builtin-extension Version ^0.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.