Clear MIT licensing and a usable README with release notes support adoption. No security policy and a single maintainer leave limited transparency and continuity if issues arise.
72%
Total Score
50
100
88
50
The package is mature at 1,278 days old with 16 releases, but only one release appeared in the last 12 months. That points to slower ongoing maintenance despite the recent release.
The repository recorded zero commits and zero active maintainers during the last three months. Although the latest release was recently published, the lack of recent commit activity raises abandonment and responsiveness concerns.
Composer is used as the build tool, which fits this PHP package, but no security-scanning tool was detected. The missing scanning is a modest supply-chain hygiene gap rather than evidence of unsafe code.
The repository has no SECURITY.md or other security policy. This makes vulnerability reporting and coordinated fixes less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.2 | — | — |
phpdocumentor/reflection-docblock Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.