The artifact is small and clearly tied to its repository, with no install-time scripts. Its source has little activity and no security policy; use dreamfactory/package-installer instead.
15%
Total Score
75
50
75
Packagist marks the entire package as abandoned and names dreamfactory/package-installer as its replacement. This is a severe adoption risk because future maintenance is directed elsewhere.
The package was last released in January 2014 and has had no releases in the last 12 months. This strongly indicates abandonment for a dependency intended for current projects.
The repository recorded no commits and no active maintainers in the last 3 months. Although it was pushed in December 2023, current maintenance activity is absent.
The linked repository has no security policy. This weakens vulnerability-reporting transparency, adding a secondary concern alongside the package's abandonment indicators.
The assessed version is 1.2.3, but the registry reports 1.0.1 as the latest version. This inconsistency reduces confidence that the assessed release is tracked and maintained normally.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kisma/kisma Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.