It has a clear license and a recent, steady release record. Maintenance is concentrated in one contributor, with no security policy or automated security scanning, so long-term resilience is limited.
72%
Total Score
67
100
93
75
The repository is owned by a personal GitHub account rather than an organization, so there is no provided evidence of institutional backup for the single maintainer.
All 8 recent commits came from one contributor, so maintenance and release continuity depend heavily on a single person.
Composer is used for builds, but no security scanning tools were detected; this is a meaningful security-process gap despite active development.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
No GitHub Actions workflows were present, so the audit found no workflow hazards; this also provides no evidence of automated checks or release safeguards.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xqkeji/xq-app-admin Version ^1.0 | — | — |
xqkeji/xq-com-tinymce Version ^1.0 | — | — |
xqkeji/xq-com-treegrid Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.