The package includes a clear license and substantial README, while the repository is active and backed by an organization. Security documentation and scanning are absent, so long-term maintenance and review capacity remain limited.
62%
Total Score
88
100
88
83
This is the first release, published 0 days ago, so there is no track record for maintenance or release reliability yet.
All five recent commits came from one contributor, concentrating practical maintenance knowledge and increasing continuity risk; organization backing partly compensates.
Composer is used for builds, but no security scanning tools were detected, leaving an avoidable review and monitoring gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.