The package has a clear README, a matching repository, and a simple dependency set. Its last release was about four years ago and the repository has had no commits in the past three months, so future maintenance is uncertain.
55%
Total Score
50
100
81
83
The package and repository are owned by the same individual account rather than an organization. That is consistent ownership, but it indicates a limited backing structure and leaves less visible maintainer capacity.
The package has had no release in about four years, with three releases clustered on its first release date and none in the past 12 months. This is a meaningful maintenance concern, though the small package scope may reduce the need for frequent releases.
The repository had no commits and no active maintainers in the past three months. This is direct evidence of currently inactive development and materially raises the risk of slow fixes.
There are three open issues but no new or closed issues and no pull-request activity in the past month. This suggests limited current project activity, although the issue count is small.
Composer is used as a build tool, but no security-scanning tooling is present. The missing scanner is a modest transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.