Unfit to use: Packagist marks this package abandoned and points to a replacement, so new projects should depend on imagewize/warder-cookie-consent instead. The replacement repository is active and the release is well documented, but those strengths do not offset the package-level deprecation.
20%
Total Score
100
100
75
67
Packagist marks the entire package as abandoned and names imagewize/warder-cookie-consent as its replacement. Package-level deprecation is a severe dependency-maintenance risk even though the assessed release itself is current.
The repository name does not match this package and its README does not mention the package, so the linkage is not transparent. This is especially relevant because the registry identifies this package as replaced by that repository’s package.
Composer build tooling is present, but no security-scanning tools were detected. This is a security-process gap, though the active repository and clean workflow analysis provide some compensating evidence.
The repository has no security policy, leaving vulnerability reporting and response guidance undocumented. This is a transparency gap for a package that handles website consent behavior.
All three workflows lack top-level token-permission declarations, so their GitHub Actions permissions are not explicitly minimized. No workflow requests top-level write access, which limits the practical concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.