The stable MIT artifact is clearly identified, has a usable README, and avoids install-time scripts. Its maintenance appears to have stopped after 2018, with no recent commits and no security policy; adoption carries substantial abandonment risk.
45%
Total Score
63
100
78
75
Only one registry publishing maintainer is listed, which is a thin publishing base. The organization-owned repository provides some backing, so this is not treated as a severe standalone risk.
Only two releases exist, with the latest published over 8 years ago and none in the last 12 months. This strongly suggests the package is no longer actively maintained.
There were zero commits and zero active maintainers in the last 3 months, reinforcing the release-history evidence that active maintenance has stopped.
There are no open issues or pull requests and no activity in the last month. This is consistent with a dormant project, though it does not show unresolved maintenance problems.
The repository has no stars, one watcher, and three forks, indicating limited adoption and little supporting community evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.