The source repository matches the package, includes tests, and was pushed recently. Releases are stable and licensed, but recent commit activity is currently absent.
45%
Total Score
75
100
83
75
The package is flagged as borrowing the identity of the much more downloaded wikimedia/composer-merge-plugin, and borrows_lookalike_identity is true. Although artifact overlap is zero and the repository matches this package, the naming evidence remains a serious adoption risk.
There were zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, even though the repository was pushed recently and the package released within the last year.
The repository uses Composer for builds, but no security scanning tools were detected. The build tooling is appropriate, while the missing scanning is a minor transparency gap.
No repository security policy was found, leaving vulnerability reporting guidance undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.