It is clearly licensed, has a matching repository, and installs without lifecycle scripts. The tiny project has no recent commits, security policy, tests, or release notes, so long-term maintenance is uncertain.
68%
Total Score
50
100
94
83
Only one registry publishing account is listed, indicating a thin publishing base; the linked repository is user-owned rather than organization-owned, so no organizational compensation is shown.
The registry namespace and repository owner match, but the owner is a user account rather than an organization, providing limited evidence of durable project backing.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance concern that conflicts with the recent registry release cadence.
Composer is used as the build tool, but no security scanning tools are present; this is a modest transparency and maintenance gap for a package with a small contributor base.
The repository has no security policy, leaving no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xqkeji/composer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.