Frequent releases and an active, organization-owned repository support continued maintenance. The missing security policy and absent security scanning leave transparency and response processes less established.
68%
Total Score
100
100
78
83
The repository name does not match the package name and its README does not mention this package, creating uncertainty that the linked repository is the actual source for this release.
The repository has no stars, forks, or watchers. This is weak supporting evidence, but popularity alone does not determine the health of a small package.
Composer is used as a build tool, but no security scanning tools are present, leaving automated detection coverage limited.
The repository has no security policy, so consumers are given no documented process for reporting vulnerabilities or receiving security fixes.
Version 3.0.1 is a stable major release and not a prerelease, although the recent prerelease share is high at about 57%, which adds some release-process uncertainty.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103 || ^104 | — | — |
trustcomponent/trustcaptcha-php Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.