Usable with caveats: the package is licensed, clearly backed by an organization, and has a matching source repository, but it has had no release or commit activity since December 2022. Its small footprint and lack of security tooling add maintenance risk for a production WordPress dependency.
55%
Total Score
75
75
50
The package has nine releases since January 2020, but none in the last 12 months and the latest release was in December 2022, indicating prolonged release inactivity.
There were no commits and no active maintainers in the last three months, reinforcing that maintenance has effectively stopped for the currently observed period.
Composer is used for project tooling, but no security scanning tools are configured, leaving a transparency and maintenance gap for a dependency distributed to consumers.
The repository is not archived, which is a positive sign, but its last push was in December 2022 and therefore does not offset the stale maintenance evidence.
The repository has no security policy, so users have no documented project channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version >=1.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.