This release appears reasonably safe to depend on from a maintenance and transparency perspective: it has a stable release line, 21 releases over about 3 years, 10 releases in the last 12 months, an active non-archived repository, and 12 commits from 3 active contributors in the last 3 months. The main concerns are install-time lifecycle scripts, no repository security policy or security scanning, and a workflow with top-level write permissions; the package and repository also lack tests and a changelog according to the collected scaffolding signal. These are meaningful hygiene and operational risks, but they do not outweigh the evidence of current maintenance and a repository that matches and documents the package.
76%
Total Score
70
100
89
70
The package declares post-autoload-dump, post-install-cmd, and post-update-cmd scripts, which execute during Composer operations and increase installation-time behavior and review risk.
Only one account has registry publish access. This is a modest publishing bus-factor concern, but registry access is administrative evidence and is partly offset by the repository's three active contributors.
The collected scaffolding signal reports no README, tests, or changelog in the package or repository, although GitHub Releases are used. The lack of tests and changelog reduces transparency and verification coverage.
The repository is owned by a personal user account rather than an organization. This provides less institutional continuity than organization backing, although recent activity shows the project is currently maintained.
The top contributor accounts for about 58% of recent commits, but two additional contributors account for the remaining 42%. The concentration warrants monitoring but is not severe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
evolution-cms/evolution Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.