The last registry release was nearly eight years ago, and no contributors were active in the past three months. The organization-backed repository is not archived and includes release notes, but it does not clearly identify this package in its name or README.
45%
Total Score
63
100
71
75
The latest release was nearly eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a package developers may need to maintain or update.
There were no commits and no active maintainers in the past three months. Combined with the old latest release, this materially increases abandonment risk.
There were no new or closed issues or pull requests in the past month. With no recent commits, this suggests little current maintenance activity.
The repository name does not match the package name and its README does not mention the package. Although a subpackage can legitimately use a different monorepo name, the ownership relationship is not clearly established here.
The repository uses Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.