Splash Bundle for SF Fos User
60%
Total Score
caution
Usable with caveats: no registry release since April 2023 despite a recent repository push.
Only five releases are recorded, all ending in April 2023, with no releases in the last 12 months. This materially raises staleness risk despite the repository being active more recently.
The package defines post-install and post-update Composer scripts, adding execution during dependency operations. No further evidence shows those scripts are unsafe, so this is a limited supply-chain hygiene concern.
The repository shows zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance. The recent repository push provides some contrary evidence but does not establish sustained activity.
The repository name matches the package, but the README does not mention the package name. That leaves some uncertainty about the repository-to-package relationship.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
splash/php-bundle Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.