A clear README, release notes, and simple dependency profile make integration easier. The repository is not archived and is organization-backed, but missing security scanning and a thin source-repository test picture limit confidence.
58%
Total Score
50
100
81
75
There were zero commits and zero active maintainers in the last three months. For a package that has only one release, this is a meaningful maintenance and abandonment concern.
The package is 211 days old but has only one release, with no established release cadence. That limited history makes long-term maintenance harder to judge.
The repository has one open issue and two open pull requests, but no issues or pull requests were opened or closed in the last month. This supports the concern about limited recent activity.
The repository name matches the package, but the README does not contain the package name. This creates a small concern about how clearly the source repository identifies the published package.
Composer is used as a build tool, but no security-scanning tools are present. That is a modest transparency and maintenance gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.