Risky to adopt: this package has had only one release, with no new release for over five years. Its own documentation says it was not suitable for production and subject to change, while the repository has no recent activity or security policy.
35%
Total Score
50
42
50
There has been only one release, published over five years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
No declared license or license file was found in the package or repository, leaving the legal terms for adoption unclear.
The package includes a usable README, but it explicitly says the code was not suitable for production and was subject to change; no tests or changelog are present, though their absence from the artifact is not itself a packaging defect.
There are no open issues or pull requests and no issue or pull-request activity in the last month. For a project already unchanged for years, this provides no evidence of active maintenance.
The repository name matches the package, which is compensating evidence, but the README does not mention the package name. This leaves some uncertainty about the repository-to-package relationship.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.