The package includes clear usage documentation, a license, release notes, and no install-time scripts. Its short history and one-person commit activity leave maintenance capacity unproven, while organization backing provides some continuity.
68%
Total Score
67
100
83
88
The package is 61 days old with only one release, so there is not enough history to demonstrate sustained maintenance or release reliability.
All recent commits come from one contributor, creating a narrow individual bus factor; the organization-owned repository provides some compensating continuity.
Only one commit from one active maintainer was recorded in the last three months, which leaves ongoing maintenance capacity unproven for a package with just one release.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not determine the health of a small package.
Composer build tooling is present, but no security scanning tools are configured, leaving security-maintenance practices less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rosgear/ge2-composer-plugin Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.