The package has a clear README, tests, and a substantial source tree, while recent activity shows 19 commits and four merged pull requests in the last month. Two contributors are active, but 17 of 19 commits come from one person and no security policy or scanning is present.
78%
Total Score
67
88
83
The manifest declares GPL-2.0-or-later, while the artifact license file was detected as GPL-3.0. A license file is present, but the declaration and detected text do not align, creating a transparency and compliance caution.
The repository owner is an individual account rather than an organization, so the concentrated contribution pattern is not compensated by visible organizational backing.
Two contributors were active in the last three months, but one made 17 of 19 commits. The second contributor provides some continuity, while the strong concentration remains a maintenance caution for a user-owned project.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning reduces automated supply-chain hygiene, though it is not evidence of a defect by itself.
The repository has no security policy. For an extension handling AI connections, OAuth credentials, bearer tokens, and backend functionality, this is a meaningful transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
madj2k/ai-core Version ^2.0 | — | — |
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.