This is a generally healthy package to depend on: it has a stable 1.1.0 release, an active non-archived organization-owned repository, recent commit and pull-request activity, tests, Composer-based build tooling, Dependabot scanning, and no install-time lifecycle scripts. The main concerns are a sparse release history, only one active contributor in the last three months, very low repository popularity, and missing security-policy and top-level workflow permission declarations. These warrant monitoring and review of maintenance continuity, but do not currently indicate abandonment or an unfit dependency.
78%
Total Score
90
100
89
80
The package is about 4 years and 8 months old but has only 3 releases, with a median interval of about 849 days and only 1 release in the last 12 months. This indicates slow release cadence and some maintenance uncertainty, despite the recent release.
All 6 commits in the last 3 months came from one contributor, producing a complete concentration of recent activity. This is a meaningful continuity risk, although organization ownership may allow maintenance to be handed off.
The repository has 0 stars and 0 forks, with 2 watchers. Low popularity is not disqualifying for a niche plugin, but it provides little external evidence of broad community adoption.
No security policy is present in the repository, reducing transparency about vulnerability reporting and coordinated disclosure.
The only workflow lacks top-level token permissions declarations. No write permissions were observed, but explicit least-privilege declarations would provide stronger assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpcq/plugin-api Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.