Its small dependency footprint limits integration complexity. The repository could not be found, so maintenance and provenance cannot be verified.
12%
Total Score
100
17
Packagist marks the entire package as abandoned, with no replacement identified; this is a severe adoption risk because future maintenance is not expected.
The package has only three releases, with the latest published about 9 years ago and none in the last 12 months. Its roughly 2-month historical release interval does not compensate for the long period without updates.
Version 0.1.2 is not a prerelease, but it remains below a stable major version and has not advanced since the old release history ended. This adds maturity risk alongside the abandonment signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.