The single maintainer and lack of security scanning provide limited ongoing oversight. Clear licensing, documentation, and a matching source repository help, but the package has not shown recent maintenance.
45%
Total Score
25
100
81
83
The latest release was published about eight years ago, with no releases in the last 12 months and only three releases overall. This is substantial abandonment risk for a dependency, despite the package having a long history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the stale release history. No provided signal shows compensating recent maintenance.
Only one registry publishing maintainer is listed, leaving a thin publishing base and increasing continuity risk. The linked repository is user-owned rather than organization-backed, so there is no provided organizational support to offset this.
Composer build tooling is present, but no security scanning tools are reported. The missing security automation adds a modest maintenance concern alongside the absence of recent activity.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a meaningful hygiene gap for a plugin that handles application functionality, though it is not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version >=1.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.