The package is substantial and clearly documented for consumers. Strong release activity and organization backing help, but the release is a prerelease and all recent commits come from one bot; the license files also disagree.
68%
Total Score
83
79
50
The artifact contains a license file and the repository also has one, but the manifest declares GPL-2.0-or-later while the detected artifact license is GPL-3.0. The mismatch warrants checking compatibility before adoption.
The package runs a post-autoload-dump install-time script. This is a supply-chain and installation review point, though one script alone is not evidence of poor maintenance.
One contributor made all 27 recent commits, creating a clear concentration risk. Organization ownership provides some handoff capacity but does not remove the short-term dependency on one contributor.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tools were detected. That is a modest transparency and maintenance gap for a large plugin.
The repository has no published security policy. This weakens vulnerability-reporting transparency, although it does not by itself indicate abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.12 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.