Documentation and release support are solid, and the organization-backed project is still receiving updates. The small active contributor base, unpinned workflow actions, and unclear repository identity warrant extra scrutiny before adoption.
68%
Total Score
67
100
88
75
One contributor made all three commits in the last three months. Organization ownership provides some handoff capacity, but no second recently active contributor is shown, so maintenance remains concentrated.
Only three commits were made in the last three months, with one active maintainer. That shows recent activity but a relatively thin maintenance signal.
The repository name does not match the package name and its README does not mention this package. Although name differences can occur in component repositories, both signals together make package-to-source identity unclear.
Composer build tooling is present, but no security scanning tools are reported. The missing scanning is a hygiene gap rather than evidence of unsafe code.
The repository has no security policy. For a reusable server-side component, that reduces transparency around vulnerability reporting and handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0|~2 | — | — |
mwstake/mediawiki-componentloader Version ~1 | — | — |
mwstake/mediawiki-component-inputprocessor Version ~1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.