The repository includes tests, a changelog, release notes, and a working source link, while the workflow audit found no dangerous triggers or sinks. Long-term maintenance has stopped, the package is registry-deprecated, and its declared proprietary license conflicts with the repository's GPL-2.0 license.
22%
Total Score
0
58
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption risk because future fixes and support are not expected.
The last release was on 2019-07-08, with zero releases in the last 12 months. This indicates prolonged release abandonment despite the stable version format.
The repository recorded zero commits and zero active maintainers in the last 3 months. That supports the release-history evidence of inactive maintenance.
The manifest declares a proprietary license, while the repository license file is recognized as GPL-2.0. This mismatch creates material uncertainty about the terms governing the package release.
Both workflows were analyzed successfully and contain no untrusted checkout, script-injection, or dangerous-trigger findings. However, all 11 action references are unpinned, leaving a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.