The README still says “Description coming soon,” making setup and intended behavior harder to verify. Its small dependency footprint and non-deprecated, unarchived status are modest positives.
32%
Total Score
0
100
69
83
The package has had only 2 releases, with none in the last 12 months; its latest release was about 10 years ago. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no activity since 2016.
A README is present, but its description says “Description coming soon” and provides limited consumer guidance. The absence of tests and a changelog is normal for a published artifact and is not itself a gap.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these values provide little evidence of broad community support.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a secondary transparency gap, not evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.