This release appears usable and reasonably transparent: it is licensed, non-deprecated, stable, backed by an unarchived organization-owned repository, and includes a README, changelog, tests, and a clear file tree. However, the package is young at 78 days, repository activity is very thin with only one commit from one active maintainer in the last three months, and the repository has no security policy, no security scanning tools, and a workflow with top-level write permissions. The organization backing reduces the risk from individual-contributor concentration, but the limited observed maintenance activity means this is a caution-level dependency rather than a clearly mature one.
68%
Total Score
67
100
83
80
The package has four releases over 78 days, with releases in the last 12 months and a median interval of about 34 days; this is promising but still a short history for judging long-term maintenance.
All observed recent commits come from one contributor, creating concentration risk; the organization-owned repository provides some compensation because maintenance can potentially be handed off internally.
Only one commit and one active maintainer were observed over the last three months, which is weak evidence of ongoing maintenance despite the recent push and release activity.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counters provide no external adoption signal.
Composer is used as a build tool, but no security scanning tools are present, leaving a security-process gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version 4.5.* || 5.0.* || 5.1.* || 5.2.* | — | — |
composer/installers Version ~1.0 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.