Usable with caveats: the package is documented, licensed, stable, and not deprecated or archived. However, its last release and repository update were in July 2019, with no commits or active maintainers in the last three months, so expect little ongoing support.
52%
Total Score
25
100
78
75
The package has only two releases, and the latest was published in July 2019; there have been no releases for about 7 years. This is a substantial maintenance and compatibility concern for a dependency.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the package's long period without a release. No stronger maintenance activity is provided to offset this.
The package is backed by a personal-user repository rather than an organization, so the single registry maintainer provides limited continuity if that maintainer becomes unavailable. This concern is secondary to the directly observed inactivity.
The repository has only 1 star and 1 fork, indicating limited adoption and external visibility. Popularity is supporting evidence rather than a verdict, but it provides little independent assurance for an otherwise inactive project.
Composer is used for builds, but no security scanning tooling is configured. The missing scanning is a hygiene weakness, though the absence of complex automation limits the practical impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.