The README, MIT license, exact GitHub release notes, and tiny dependency set make the package transparent and straightforward to inspect. Its single maintainer and minimal repository activity leave little evidence of ongoing support; pin this version if adopting it.
56%
Total Score
100
100
78
50
The package has had only two releases, both in July 2019, with no releases in over seven years. This is the main evidence of possible abandonment, although the stable 1.1.0 release remains available.
The repository has one star and no forks or watchers, offering little external adoption evidence. Popularity is supporting evidence only and does not outweigh the package's clear documentation.
Composer build tooling is present, but no security scanning tool is reported. This is a minor transparency gap for a small package, not evidence that the release is unsafe.
The linked repository is not archived, but its last push was in July 2019, reinforcing the release-history concern rather than showing active maintenance.
The repository has no security policy. This limits disclosure guidance but is a hygiene gap rather than a direct dependency-quality failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.