The source tree is substantial, the repository is active enough to remain unarchived, and the current version has release notes. Dependence is weakened by missing licensing, no recent commits or security policy, and uncertainty about the repository-package match.
57%
Total Score
50
70
50
No license declaration or license file was found in the package or repository, leaving reuse and redistribution rights unclear.
The package has 26 releases, but all were published on the same day and there has been no newer release over 203 days, which suggests a burst rather than an established cadence.
The repository recorded zero commits and zero active maintainers in the last three months, reducing evidence of ongoing maintenance.
The repository name does not match the package name, and no README mention was available, so ownership of the package source cannot be confirmed from this signal.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.