The package is clearly licensed and documented, and its organization-owned repository shows recent development. A security policy and automated security scanning are absent, leaving oversight less transparent for a security-sensitive account-recovery module.
62%
Total Score
83
86
75
This is a new package, 56 days old, with only one release. That limits evidence of stability and long-term maintenance.
All 21 recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some handoff capacity but does not remove the concentration.
Composer build tooling is present, but no security-scanning tools were detected. For an account-recovery module, that is a notable transparency and oversight gap.
The repository has no security policy. This is a caution for a module handling account recovery because it gives users no documented reporting path or security process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rosgear/ge2-composer-plugin Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.