Its MIT license, clear README, and non-archived organization repository provide useful transparency. No security policy or scanning setup makes changes harder to assess.
48%
Total Score
75
86
50
The latest release was over 3 years ago, with no releases in the past 12 months; this is a substantial maintenance concern for a security-focused plugin.
The repository has had no commits and no active maintainers in the past 3 months, consistent with the long release gap and increasing abandonment risk.
Composer build tooling is present, but no security scanning tools were detected; this weakens ongoing security assurance without proving the package is unsafe.
The repository has no published security policy, leaving users without a documented reporting and response process for a security-focused package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.