It has a clear license, release notes, and a matching source tree. Security scanning is absent, so keep deployment controls in your own pipeline.
76%
Total Score
67
100
89
100
The repository is owned by a user account rather than an organization, so the single-contributor concentration is not visibly offset by organizational backing.
All eight recent commits came from one contributor, leaving maintenance continuity dependent on a single person despite the recent activity.
The repository has only 2 stars and no forks or watchers; this is weak supporting evidence, but popularity alone does not outweigh its active release and commit history.
Composer is used for builds, but no security-scanning tool was detected. That leaves a useful supply-chain hygiene gap without proving the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
se7enxweb/ezpublish-legacy-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.