The package is only 68 days old with two releases, and all recent repository commits come from one contributor. Documentation, licensing, organization backing, and a release note provide useful transparency, but no security policy is present.
68%
Total Score
67
100
88
75
The package is 68 days old with two releases and a 68-day median release interval, so its maintenance record is still limited rather than established.
One contributor made 100% of the one recent commit. Organization backing reduces the risk somewhat, but no second active contributor is evidenced.
Only one commit was recorded in the last three months, indicating limited observed development activity for a package that is still very young.
Composer build tooling is present, but no security-scanning tools were detected, leaving security-process maturity un demonstrated.
The repository has no security policy, so there is no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rosgear/ge2-composer-plugin Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.