Healthy and suitable to use, with a modest maintenance caveat: the project is actively backed by an organization, has a recent stable release, and shows ongoing work from two contributors. Issue and pull-request queues had no recorded activity in the last month, so maintenance responsiveness is not especially strong.
82%
Total Score
90
100
94
83
The repository has a substantial open queue with 126 issues and 47 pull requests, while recording no new or closed issues or merged pull requests in the last month. This raises a modest concern about responsiveness, but does not outweigh the recent release and commit activity.
The repository uses Composer for builds, but no security scanning tool was detected. This is a transparency and defense-in-depth gap, though the project still has a defined build tool and a separate security policy.
The only workflow lacks top-level token permissions, so its effective permissions are less explicit than ideal. No top-level write permissions were detected, limiting the severity of this concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.