Documentation and tests are present, with compatibility and rollback recorded. MIT licensing and no install scripts reduce adoption friction, but limited operating history and security process leave more uncertainty than a mature dependency.
70%
Total Score
67
100
88
83
The package is only 2 days old and has one release, so there is little evidence yet about long-term maintenance or release consistency.
One contributor made all observed commits, creating a concentrated maintenance dependency; organization backing provides some capacity to hand work off.
Only one commit was observed in the last 3 months, so actual maintenance activity is still minimally demonstrated.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest process gap for a dependency release.
The repository has no security policy, reducing transparency about how users should report and receive fixes for security issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.