The README and release notes give consumers useful documentation, and the organization-backed repository is still active rather than archived. The commercial, closed-source delivery model limits transparency, while the minimal artifact leaves little evidence beyond the listing.
61%
Total Score
75
86
50
The artifact contains only LICENCE, README.md, and composer.json, consistent with the README's statement that the module source is delivered after purchase, but this limits what can be independently inspected before adoption.
This is a young package with one release, all published 96 days ago, so there is not yet enough history to demonstrate sustained maintenance.
The linked repository recorded zero commits and zero active maintainers in the last three months, leaving no observed recent development activity after the initial listing.
Composer is used for the project build, but no security scanning tools are present. This is a modest hygiene gap rather than evidence that the release is unsafe.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities in a commercial extension.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.