The package includes tests, a changelog, clear documentation, and matching license files. Its repository lacks a security policy and automated security scanning, while installation runs a post-install command.
82%
Total Score
100
100
89
67
A post-install command runs during installation. The signal does not show what it does, but install-time execution adds a modest supply-chain and reproducibility concern.
The repository has zero stars, forks, and watchers. That provides little external validation, but popularity is supporting evidence and does not outweigh the package's recent activity and documentation.
Composer is used as a build tool, but no security scanning tool is detected. The missing scanning process is a modest transparency gap, not evidence of an unsafe release.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the active repository and documented project partly compensate for the gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0 | — | — |
phpoffice/phpspreadsheet Version ^5.3 | — | — |
webcraftdg/fractal-cms-core Version ^v2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.