The package includes a clear README, license, release notes, and a security policy. Its small dependency set and absence of install scripts reduce integration risk, but repository adoption is minimal and automated security scanning is not reported.
70%
Total Score
50
100
88
100
One contributor made all two recent commits, leaving maintenance dependent on a single active person without evidence of a broader handoff path.
Two commits occurred in the last three months, so activity has not stopped, but the volume is modest for a package receiving recent releases.
The repository name matches the package, which supports the link, but its README does not mention the package name; that weakens confidence that the repository documentation fully identifies the published package.
Composer build tooling is present, but no repository security scanning tool is reported, leaving a meaningful security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
se7enxweb/ezpublish-legacy-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.