The package is clearly documented, licensed, and backed by an organization, with a focused dependency profile. It is brand new with no demonstrated ongoing commit activity, and the repository has no security policy or scanning tools.
68%
Total Score
75
100
88
88
This is the first release and was published only hours ago, so there is no release history to demonstrate sustained maintenance. The lack of history is understandable for a new package but remains an adoption risk.
There were no commits or active maintainers in the three months measured, but the repository was created at the release time. This confirms that ongoing maintenance is not yet demonstrated rather than proving abandonment.
Composer build tooling is present, but no security scanning tools were detected. For a small new module this is a hygiene gap, not a severe dependency risk by itself.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations. This is a modest concern for a package that changes administrator passwords.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.