Composer plugin for installing of assets.
68%
Total Score
caution
Usable with caveats: maintenance has gone quiet since the June 2025 release.
The package has existed since December 2016 and has 11 releases, but none in the last 12 months; the latest release was in June 2025. This indicates slowing maintenance rather than abandonment by itself.
The repository had no commits and no active maintainers in the last 3 months, consistent with the quiet release cadence. This raises maintenance and abandonment risk.
There were three open issues but no new or closed issues and no pull requests in the last month. The lack of recent issue movement modestly weakens evidence of active support.
The repository uses Composer build tooling, which fits the package ecosystem. No security scanning tools are configured, but that is a modest hygiene gap rather than a severe dependency risk.
The repository has no security policy. For a Composer plugin that participates in installation and asset handling, this is a transparency gap, though it is not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.