The small codebase has a clear README, matching repository, stable version, and organizational backing. Security scanning and a security policy are absent, and the project shows no activity since April 2023. Pin this version only if its mature, narrow scope fits your needs.
58%
Total Score
75
100
83
83
The package has only three releases and none in the last five years; its latest registry release was in May 2021. This is meaningful evidence of stalled maintenance, though the stable version may suit a mature, narrow plugin.
There were no commits and no active maintainers in the last three months, consistent with a project whose latest push was in April 2023. This raises abandonment risk despite the repository not being archived.
The repository has zero stars and one fork, indicating limited visible adoption. Popularity is supporting evidence rather than a verdict, so this only modestly lowers confidence in project maturity.
Composer is used as a build tool, but no security scanning tooling is configured. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, but it is not severe for a small, mature plugin.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.