The MIT license, focused dependency set, and included tests make the package straightforward to inspect and integrate. Its low adoption, absent security policy, and long period without updates warrant extra caution for production use.
55%
Total Score
50
100
72
75
The package has had only two releases, both in April 2015, with no releases in about 11 years. This is a substantial maintenance and abandonment concern despite the short initial release interval.
There were no commits and no active maintainers in the last 3 months, consistent with the repository's last push being about 11 years ago. This is the strongest maintenance concern in the collected evidence.
The repository has only 3 stars and 1 fork, providing little evidence of broad community adoption or a strong external maintenance base.
Composer build tooling is present, but no security scanning tools were detected. For an old Magento module, the missing security checks modestly reduce transparency.
The linked repository is not archived, which is better than an explicit abandonment state. Its last push was in April 2015, so the non-archived status does not compensate for the stale activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.