Its five-file layout, readable installation guidance, and lack of install-time scripts keep the package simple to integrate. The repository has no security policy or security scanning, leaving maintenance and security practices difficult to verify.
38%
Total Score
50
86
75
The latest release was published in May 2016, and there have been no releases in roughly 10 years. Four total releases provide little evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap. The repository is not archived, but there is no observed recent activity to offset the concern.
Composer is used as a build tool, but no security scanning tools are configured. That weakens evidence of routine security maintenance, though it does not by itself indicate a vulnerable release.
The linked repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a transparency gap for a package that integrates with Composer.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fxp/composer-asset-plugin Version ^1.1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.