This is a healthy, mature release with a long publication history, regular recent releases, stable versioning, an active non-archived organization-backed repository, recent contributions from three maintainers, and solid package scaffolding including tests and a changelog. The main concerns are an unresolved issue backlog, no repository security policy or security-scanning tooling, and a relatively small package-level publishing maintainer list, though the latter is substantially mitigated by the organization-backed repository and distributed recent activity. There are no lifecycle scripts, deprecation notices, or unusually large runtime dependency surface to add supply-chain or maintenance concern.
82%
Total Score
90
100
94
90
The repository has 18 open issues, while two new issues were opened and none were closed in the last month; one pull request was merged. This indicates a real unresolved maintenance backlog and warrants caution, though it is not evidence of abandonment by itself.
Composer is used as a build tool, but no security-scanning tools are detected. The missing scanning coverage is a transparency and preventive-maintenance gap, though it is not a direct health verdict.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, creating a genuine but moderate maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.7 ||^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.