The repository is tiny and has no security scanning or published security policy. Its Apache-2.0 licensing, clear README, stable version, and recent registry releases provide useful transparency.
65%
Total Score
67
100
89
50
Only one registry account has publishing access. That is a limited publishing base, though the matching repository ownership and recent release activity partly compensate.
The repository had no commits and no active maintainers in the past three months. Although the current release was recently pushed, the short-term development record is thin.
The repository has zero stars and forks and only one watcher. This is supporting evidence of a small project, but it is not decisive because popularity is not required for a healthy package.
Composer is used for the build, but no security scanning tools were detected. That leaves a meaningful transparency and maintenance safeguard gap.
The repository has no published security policy, so users have no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xqkeji/xq-app-admin Version ^1.0 | — | — |
xqkeji/xq-com-bootstrap-select Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.