There is no security policy or automated security scanning, leaving maintenance safeguards unclear. The package is licensed, documented, correctly linked to its organization, and has a GitHub release, which offsets some concern.
61%
Total Score
67
100
88
75
The package is only 58 days old and has one release, so its maintenance record and compatibility history are not yet established.
All recent commit activity comes from one contributor. Organization backing provides some handoff capacity, but no second active contributor is shown.
There was only one commit in the last 3 months, so the project shows little observed maintenance activity beyond its initial release.
Composer is used for builds, but no security-scanning tooling was detected, leaving an important maintenance safeguard unverified.
The repository has no security policy, so reporting and handling of vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rosgear/ge2-composer-plugin Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.