The package is clearly identified and has a usable README. No security policy or scanning evidence reduces transparency, while organization backing offers some context.
43%
Total Score
100
67
50
The latest release was published in November 2014, with no releases in the last 12 months and only two releases overall. This is strong evidence of abandonment risk despite the package not being deprecated.
Composer is used for the build, but no security-scanning tooling was detected. The missing scanning is a transparency and hygiene gap, not evidence of malicious behavior.
The repository is not archived, which keeps the project technically available, but it was last pushed in February 2016. That long period without repository activity reinforces the stale release history.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This matters more for an old package with little recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version 1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.