It includes a useful README and a declared OSL license, but installation runs a post-install command and pulls 11 runtime dependencies. The published artifact is substantial, though repository verification was unavailable.
38%
Total Score
50
75
75
The package has only one release, first and latest published 12 years ago, with no releases in the last 12 months. That strongly raises abandonment and compatibility risk.
The package declares 11 runtime dependencies, including Composer, Magento installers, and frontend preprocessing tools. That increases compatibility and maintenance surface for an already inactive release.
A post-install-cmd script runs during installation, adding execution and reproducibility considerations for consumers. The signal does not show that the script is unsafe, so this is a caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafo/lessphp Version 0.4.*@dev | — | — |
leafo/scssphp Version dev-master | — | — |
composer/composer Version dev-master | — | — |
mikey179/vfsstream Version * | — | — |
richthegeek/phpsass Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.