The package has clear documentation, a matching source repository, and an explicit license. Its registry history is thin and recent repository activity shows no commits, while security scanning is not configured.
67%
Total Score
50
79
100
The package has only one release, published about 23 months ago, with no releases in the last 12 months. That provides limited evidence of an established maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last three months. This suggests limited current development, although the repository is still present and not archived.
Composer build tooling is present, but no security scanning tools are configured. For a small legacy extension this is a hygiene gap rather than a severe dependency risk.
Version 0.1.1 is not a prerelease, but it remains below 1.0 and the package has only one published version, so long-term stability is not strongly demonstrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
se7enxweb/ezpublish-legacy-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.