The package includes clear usage documentation, release notes, and repository tests. Its small but active contributor base and Dependabot coverage help, while the license mismatch and unpinned workflow actions deserve attention.
78%
Total Score
88
100
94
75
The registry declares MIT, but the artifact's detected CC0-1.0 license does not match that declaration. Both the artifact and repository contain license files, so this is a clarification issue rather than an unlicensed release.
One contributor made 12 of 13 recent commits, creating a concentrated bus factor. The second active contributor and organization-owned project provide some compensation, so this is a modest concern rather than a severe risk.
No repository security policy was found, leaving disclosure and vulnerability-handling expectations undocumented.
All five workflows were analyzed without high-confidence findings, dangerous triggers, or broad top-level write permissions. However, all 13 referenced actions are unpinned, which weakens build reproducibility and makes this a workflow-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.