The six-file package is easy to inspect and has concise usage documentation. Organization backing and release notes help, but long-term maintenance evidence is absent; verify the GPL terms before adoption.
44%
Total Score
50
64
50
Only two releases were published, both in March 2019, with no release in more than seven years. This is strong evidence of abandonment for a package developers may need to maintain over time.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being more than seven years ago. No provided maintenance signal compensates for this inactivity.
The manifest declares GPL-2.0-or-later, while the artifact license file was detected as GPL-3.0. Although a license file exists, the mismatch creates avoidable uncertainty about the terms governing this release.
The repository has 4 stars and 1 fork, indicating a small user and contributor footprint. Low popularity is only supporting evidence, but it compounds the limited maintenance signal.
Composer is used for the build, which supports reproducible package structure, but no security-scanning tooling was found. This is a modest transparency and hygiene gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.