The package includes clear consumer documentation and a license, with a substantial 190-file source tree. Missing repository security scanning and a security policy are modest transparency gaps, but organizational backing and recent activity reduce abandonment concerns.
86%
Total Score
100
94
83
Composer build tooling is present, but no security-scanning tools were detected. This is a modest supply-chain transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving no documented public process for reporting and handling vulnerabilities.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-23081 mediawiki/data-transfer is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.39.0 - 1.39.11, 1.41.0 - 1.41.3 and 1.42.0 - 1.42.2. | 1.39.0 - 1.39.111.41.0 - 1.41.31.42.0 - 1.42.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0.1 | — | — |
psr/simple-cache Version 1.0.1 | — | — |
composer/installers Version ^2|^1.0.1 | — | — |
phpoffice/phpspreadsheet Version 5.8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.