The repository is maintained by an organization, includes tests, release notes, a license, and a security policy. Recent activity is light and concentrated in one contributor, while all seven workflow actions are unpinned; these are manageable maintenance and build-reproducibility concerns.
72%
Total Score
83
100
88
100
The project has 26 releases since January 2019, but none in the last 12 months; this indicates a slower release cadence, although the repository shows newer activity.
Only one commit was recorded in the last three months, showing light recent development; this is a concern but not evidence of abandonment by itself.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency gap rather than a severe maintenance concern.
Both workflows were fully analyzed with no detected dangerous triggers, sinks, or audit findings. However, all seven action references are unpinned, reducing build reproducibility and leaving action versions less controlled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.