The package is licensed, documented, and has a small dependency surface. Its tiny community and lack of a security policy provide little support for long-term maintenance.
38%
Total Score
50
100
72
75
Only three releases were published, with the latest in June 2018 and none in over eight years. This is strong evidence of abandonment risk despite the package not being deprecated.
The repository recorded no commits and no active maintainers in the last three months, and its last push was over six years ago. That makes ongoing fixes and compatibility work unlikely.
There were no new or closed issues or pull requests in the last month, while one pull request remains open. This adds to the picture of limited ongoing maintenance.
The repository name matches the package, which supports the link, but the README does not mention the package name. That weakens repository-to-package transparency slightly.
The repository has one star, zero forks, and one watcher, providing little evidence of a substantial user or contributor community. Low popularity is supporting evidence rather than decisive on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version 1.5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.