Documentation, licensing, tests, and organization backing are strong. The beta status, no commits in the last three months, and workflow hygiene issues leave meaningful maintenance and build-integrity concerns.
68%
Total Score
75
86
50
The package defines a pre-update-cmd lifecycle script, so dependency updates can execute package-controlled commands. This is a supply-chain hygiene concern, but the signal does not show a destructive or unusually broad script.
The repository shows zero commits and zero active maintainers in the last three months, despite a recent package release. That weakens evidence of ongoing maintenance and increases the risk that issues are not being addressed.
Composer build tooling is present, but no security-scanning tools are reported. This is a modest transparency and maintenance gap for a package handling remote-system integrations.
The linked repository has no security policy. That makes vulnerability reporting less transparent, though the organization-backed repository and other project documentation provide some compensation.
This is a beta prerelease, which adds compatibility risk for consumers, although only about 23% of recent releases are prereleases and the major version is established.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version >=4.4 | — | — |
webmozart/assert Version ^1.11 || ^2 | — | — |
civicrm/civicrm-core Version >=6.2 | — | — |
symfony/html-sanitizer Version >=6 | — | — |
civicrm/civicrm-packages Version >=6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.