It has clear licensing, substantial documentation, and a small runtime dependency footprint. The repository is not archived, but recent development activity is absent and its only workflow uses an unpinned action.
68%
Total Score
50
100
94
50
The repository recorded zero commits and zero active maintainers in the last three months. Although the release was recently published, the lack of recent commit activity is a meaningful maintenance concern.
Composer is used as a build tool, which fits the package ecosystem. No security-scanning tools were detected, leaving a modest security-hygiene gap.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it does not by itself indicate abandonment.
The sole workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but its one action use is unpinned. That leaves avoidable build-integrity risk in the release automation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.