The installer runs three Composer lifecycle scripts and depends on ten runtime packages, increasing upkeep and installation complexity. The repository could not be found, so current maintenance and build provenance cannot be checked.
38%
Total Score
100
80
50
The package has had only four releases, all clustered in March 2021, with no releases in the last five years. That prolonged inactivity is strong evidence of abandonment risk.
The package defines post-create, post-install, and post-update Composer scripts. Such scripts can be expected in an installer, but they add installation complexity and maintenance surface.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0.20 | — | — |
drupal/core-recommended Version ^9 | — | — |
cweagans/composer-patches Version ^1.6.0 | — | — |
drupal/core-project-message Version ^9 | — | — |
drupal/core-composer-scaffold Version ^9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.