Package Health

xqkeji/composer

There is no published security policy or automated security scanning, leaving project security processes unclear. The package is licensed and documented, with regular releases and recent commits; its maintenance depends on one contributor.

Latest 1.1.44PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The repository owner is an individual account rather than an organization. Combined with one active contributor, this provides no visible organizational redundancy for maintenance.

Repo bus factorcaution

All 33 commits in the last 3 months came from one contributor, leaving maintenance and continuity dependent on a single person. No organizational backing is shown to compensate for that concentration.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools were detected. For a package distributed as a dependency, that leaves an avoidable security-process gap.

Security policycaution

The repository has no security policy. This makes vulnerability reporting and response expectations unclear, though it is a process concern rather than evidence of a malicious package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

xqkeji.cn

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
19 hours ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform