The package is clearly licensed and has a small dependency footprint. Its source layout is present, but the lack of tests and security scanning leaves little evidence of ongoing quality control.
42%
Total Score
0
60
50
The latest release was published in October 2019, and there were no releases in the following 12 months, indicating prolonged inactivity for a package developers may depend on.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The package includes a README and has a GitHub release for this version, but it has no tests or changelog; the missing tests reduce maintenance confidence, while the missing changelog is normal for published artifacts.
Composer is used as a build tool, but no security scanning tools are configured, leaving less evidence of ongoing project hygiene.
The repository has no security policy, which weakens transparency for reporting and handling security issues in a developer-facing SDK.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nabu-3/composer-installer-plugin Version >=3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.