The package includes a README, release notes, a changelog, and a declared license, with no install-time scripts. Its absent security policy and security scanning reduce independent assurance.
64%
Total Score
67
81
83
The repository owner is an individual user rather than an organization, so there is no provided project-backing evidence to offset the concentrated contributor activity.
The package is young at 107 days old but has had three releases, including three in the last 12 months, with a median interval of about 25 days. This shows recent publishing activity but limited long-term history.
One contributor made all 10 commits in the last three months, giving the project a single-person maintenance dependency without organizational backing shown by the signal.
The repository name does not match the package name and its README does not mention the package. Although name differences can occur in related repositories, this combination makes package ownership less transparent.
Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap for a maintained extension, not evidence of a severe defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mavenbird/module-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.