Its three-file tree and one runtime dependency keep the integration surface small. No security scanning or security policy is visible, leaving maintenance and incident response weak.
38%
Total Score
0
25
50
The package has no declared license and no license file in either the artifact or repository. Developers cannot clearly establish permission to use or redistribute it.
This is the only release, published about 7 years ago, with no releases in the last 12 months. That strongly suggests the package is effectively abandoned.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no activity since 2019.
The package has no README, which is a meaningful transparency gap for a library consumers must integrate; the absence of tests and a changelog is normal for a published artifact.
Composer is used for the build, but no security scanning tools are configured. This is a modest process gap rather than a standalone dependency blocker.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.