The source still includes tests, a changelog, release notes, and a usable README. However, the registry package is deprecated, has had no release for over eight years, and its workflows use unpinned actions.
22%
Total Score
50
64
100
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency despite the repository remaining available.
The latest registry release was published in June 2018, and there have been no releases in the past 12 months. The long gap materially increases abandonment and compatibility risk.
The package declares a proprietary license, while the repository license file is recognized as GPL-2.0. This mismatch makes the release's licensing terms unclear.
The repository recorded no commits and no active maintainers in the last three months. Although it was pushed recently, the measured activity does not show ongoing development.
Both workflows were analyzed successfully and have no untrusted checkouts or injection findings, but all 11 referenced actions are unpinned. That leaves routine build inputs exposed to change over time.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.