The package includes a usable README, a stable release, and no install-time scripts. Its very small project footprint, absent recent maintenance, missing security policy, and license mismatch make long-term dependency risk high.
38%
Total Score
50
100
67
75
The latest release was published in January 2018, with no releases in the following 12 months and only two releases overall. This is strong evidence of abandonment risk for a dependency.
There were no commits and no active maintainers in the last three months. Combined with the old last push, this indicates a strong abandonment concern.
A license file is present, so this is not an unlicensed release; however, it identifies MIT while the manifest declares LGPL-3.0+, creating a material licensing ambiguity.
The repository has one star, no forks, and five watchers. Popularity is only supporting evidence, but this very small footprint provides little evidence of community support.
The repository uses Composer, showing basic build tooling, but has no security-scanning tools. This is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao-components/installer Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.