The release is clearly licensed, documented, and accompanied by version-specific notes. Its low popularity and lack of repository security scanning leave less independent review than larger projects.
78%
Total Score
67
100
89
100
The repository is owned by the se7enxweb user account rather than an organization, so the single-contributor concentration is not visibly supported by a broader organizational maintenance structure.
One contributor made all commits during the last 3 months, giving the project a low bus factor and creating a real continuity risk despite the recent activity.
The repository has only 2 stars and no forks or watchers, so there is little visible external adoption or review. Popularity is supporting evidence rather than a verdict, but this modestly reduces confidence in project maturity.
Composer is used for builds, but no repository security-scanning tool was detected. The presence of a security policy partly offsets the gap, though automated coverage is still limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
se7enxweb/ezpublish-legacy-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.