The package includes a README, tests, and a small dependency set, but install-time hooks add operational exposure. Prefer the specifically named successor package for new projects.
18%
Total Score
100
60
75
Packagist marks the entire package as abandoned and names interactiv4/composer-installer as its replacement. This is a severe adoption risk because the release is no longer the intended dependency target.
The latest release was published in May 2022, with no releases in the last 12 months despite the package being about 6 years and 7 months old. This supports the abandonment concern.
The package defines post-install and post-update Composer hooks, so installation and updates execute package-controlled actions. Such hooks may be expected for an installer package, but they increase operational exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/composer Version ^2.1.0 | — | — |
interactiv4/composer-installer-deployed-package Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.