The release includes tests, a changelog, and a clear MIT license. However, no recent maintenance evidence is available, so compatibility and abandonment risks are substantial for a Composer plugin.
40%
Total Score
25
86
75
The repository recorded zero commits and zero active maintainers in the last three months, consistent with more than five years since its last push. This is a strong abandonment and compatibility concern.
The package has had no releases in over five years, with all five releases clustered on October 26, 2020. That makes ongoing compatibility support unlikely despite the stable 2.0.0 version.
There were no new or merged pull requests and no issue activity in the last month. With the repository already showing prolonged inactivity, this provides no evidence of active support.
The project uses Composer build tooling, which fits the package ecosystem, but it has no detected security scanning. That is a minor hygiene gap rather than a standalone adoption blocker.
The repository has no security policy. This is a transparency and reporting gap, though it is secondary to the much stronger evidence of long-term inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.