Usable with caveats: the repository is active, identifiable, licensed, and has clear installation documentation, but this is a very new package with only one release and a small, concentrated contributor base. The lack of a security policy adds a transparency gap.
72%
Total Score
67
100
86
83
The repository is owned by an individual user rather than an organization, so the small maintainer base and concentrated recent activity represent the actual observed continuity of the project.
This release is from a package only 27 days old with one release and no established release cadence, so its maturity and long-term maintenance are not yet demonstrated.
Two contributors are active, which provides some continuity, but one contributor accounts for 80% of recent commits, leaving maintenance somewhat concentrated.
Composer is used as a build tool, but no security scanning tools are configured; this is a modest transparency and maintenance gap rather than evidence of abandonment.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities in an extension that connects to OpenSearch.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version >=1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.