The package is small, clearly identified, and easy to inspect, with a matching repository and Apache-2.0 licensing. Its long-term resilience is limited by concentrated ownership and sparse security practices.
67%
Total Score
50
92
83
One contributor made all commits in the last 3 months, leaving no demonstrated maintainer redundancy if that person becomes unavailable.
The repository had only 1 commit in the last 3 months, so maintenance is current but activity is too sparse to demonstrate strong ongoing development capacity.
Composer is used for build or package management, but no security-scanning tooling was detected, leaving automated security coverage un demonstrated.
The repository has no security policy, which weakens its documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xqkeji/composer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.