The artifact is small and easy to inspect, with a README, declared license, and no install-time scripts. Its lack of security tooling leaves less evidence for ongoing stewardship.
12%
Total Score
0
50
75
Packagist marks the package abandoned at package scope, with no replacement specified. That directly signals that maintainers no longer support it as a dependable dependency.
Only two releases exist, and the latest release was published over eight years ago; there have been no releases in the last 12 months. This provides little evidence of current maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Together with its archived state, this indicates no active maintenance capacity.
The linked repository is archived, and its last push was over seven years ago. An archived source project is a strong abandonment signal that outweighs the small package's basic documentation.
The repository has one star, one fork, and one watcher. Popularity is only supporting evidence, but these very low figures provide no meaningful community cushion for an abandoned package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oomphinc/composer-installers-extender Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.