MIT licensing, tests, documentation, and organization backing support adoption. Install hooks and two unpinned CI actions add maintenance and supply-chain hygiene concerns.
62%
Total Score
83
100
88
67
The package defines post-install and post-update Composer scripts. These increase install-time behavior and should be understood by consumers, even though the signal does not show that the scripts are malicious or unsafe.
Only two releases exist, with the latest on June 3, 2024 and none in the following two years. This weakens confidence in ongoing release maintenance, although the repository was pushed more recently.
There were zero commits and zero active maintainers in the three months before collection, indicating currently quiet development. The more recent repository push partially offsets, but does not remove, that concern.
Composer build tooling is present, but no security-scanning tools are reported. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
The repository has no SECURITY.md or other declared security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chrome-php/chrome Version ^1.7 | — | — |
rich-id/terms-module-bundle Version ^3.0 | — | — |
richcongress/bundle-toolbox Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.