MIDDAG Moodle adapter — platform bindings, ACL layer, and Moodle-specific implementations for middag-framework
78%
Total Score
88
100
94
75
Composer post-install and post-update scripts increase the actions performed during dependency installation and updates. No provided signal shows these scripts are unsafe or unnecessary, so they remain a supply-chain hygiene caveat.
One contributor made 97.6% of the 206 recent commits, which is highly concentrated. The second contributor remains active and the repository is organization-owned, providing some handoff capacity but not eliminating the continuity risk.
Composer build tooling is present, but no security scanning tool was detected. That is a transparency and maintenance gap, though the separate security policy and workflow checks provide partial compensation.
Workflow permissions are explicitly declared, with one workflow using top-level write access and another read-only. The explicit declarations are good hygiene, though write access is broader than strictly read-only automation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
middag-io/ui Version ^1.3 | — | — |
psr/container Version ^2.0 | — | — |
symfony/routing Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.