It has a clear MIT license, tests, a usable README, and automated security scanning. Workflow pinning and the missing security policy add smaller maintenance concerns, but they do not offset the project's abandonment signals.
10%
Total Score
50
57
67
Packagist marks the entire package as abandoned and names `package-wizard/installer` as its replacement. This is a direct warning against taking a new dependency on this release.
The package has had no releases in the last 12 months; its latest registry release was in May 2021 despite being over five years old. This indicates the published package line is inactive.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the archived and abandoned status, this strongly indicates no current maintenance capacity.
The linked source repository is archived, which prevents normal ongoing maintenance even though its last push was in January 2026. An archived project is a severe adoption risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a secondary transparency gap rather than the main reason to reject the release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.0 | — | — |
symfony/console Version ^5.0 | — | — |
andrey-helldar/support Version ^2.0 | — | — |
andrey-helldar/verbose Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.