The dependency footprint is small, and the registry does not mark the package deprecated. Its long inactivity, absent license, and install-time scripts leave too little evidence for dependable long-term adoption.
32%
Total Score
100
50
50
The latest release was nearly seven years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a package intended for ongoing use.
No license is declared, detected, or included in the package. This creates a real adoption and redistribution concern, with no provided evidence compensating for it.
The package runs pre-install, post-install, and post-update Composer scripts. Install-time execution increases supply-chain exposure and warrants caution when the project has limited maintenance evidence.
The published artifact has no README, while tests and a changelog are not expected in a packaged Docker Compose template. Missing consumer guidance is a minor usability gap rather than an abandonment signal.
Version 0.0.8 is not a stable major release, so compatibility and maturity are less established. The absence of recent releases reinforces that uncertainty.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.