The README, package structure, and organization backing provide useful context for consumers. Maintenance and transparency remain weak, so pinning this release creates a long-term compatibility risk.
43%
Total Score
75
100
61
88
The package has had no releases in more than eight years, with zero releases in the last 12 months; this is strong evidence of abandonment risk.
No license declaration or license file was detected in the package or repository, leaving the legal terms for reuse unclear.
There are no open issues or pull requests and no recent issue or pull-request activity; combined with the old last push, this supports a stale-project assessment.
The repository has zero stars and one fork, indicating limited adoption evidence, though popularity is only supporting evidence and does not determine health.
Composer is used for build or dependency management, but no security scanning tooling is present; the missing scanning is a modest transparency gap for an otherwise inactive project.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version v1.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.