The package includes tests, documentation, and release notes for this version. Workflow controls are strong, though the contributor base is concentrated and no security policy is published.
70%
Total Score
80
100
83
67
A pre-update-cmd lifecycle script runs during package updates, adding a small amount of install-time execution complexity. No other evidence shows that this script is unsafe, so this is a limited hygiene concern.
Two contributors were active recently, but the top contributor made 10 of 11 commits, or 91%. Organization backing partly offsets this concentration, but the project still depends heavily on one active individual.
The repository has 16 open issues and no issues closed in the last month, which leaves some maintenance backlog. One pull request was merged during the same period, so activity has not stopped.
The repository name matches the package, but its README does not mention the package name. The matching repository reduces the concern, though the missing README reference leaves a minor provenance gap.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
civicrm/civicrm-core Version >=6.2 | — | — |
civicrm/civicrm-packages Version >=6.2 | — | — |
systopia/de.systopia.remotetools Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.