The source project remains active and backed by an organization, with tests and release notes. Its workflow uses two unpinned actions and the repository has no security policy.
68%
Total Score
83
100
88
75
The latest registry release was over three years ago and there were no releases in the last 12 months, which raises maintenance concerns. Recent repository activity provides partial compensation but does not restore release cadence.
All three recent commits came from one contributor, leaving a thin active contributor base. Organization ownership provides some handoff capacity but does not remove the concentration concern.
The project uses Make and Composer build tooling, but no security scanning tools were detected. This is a modest transparency and assurance gap rather than a severe risk.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented.
The only workflow was fully analyzed and had no dangerous triggers, untrusted checkouts, or audit findings, but both of its two action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version 1.*,>=1.0.1 | — | — |
mediawiki/semantic-media-wiki Version 4.* || dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.