The package has no license and no security scanning, while its tiny repository offers little operational evidence. It is not deprecated, and its runtime dependency footprint is small.
35%
Total Score
50
100
64
67
Only two releases occurred, both in June 2021, with no release in more than five years. That is strong evidence of abandonment risk for a dependency.
The package has no declared license, detected license, or license file in either the artifact or repository. Consumers therefore lack clear permission to use and redistribute it.
The package contains only seven files and a single source file, providing little implementation or project context. The matching repository and complete, untruncated tree partly reduce provenance concerns.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving maintenance capacity unproven.
The repository has zero stars and forks and only one watcher, offering no meaningful supporting evidence of adoption or community visibility. Popularity is not decisive, but it reinforces the thin project history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phar-io/composer-distributor Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.