The plugin has a clear README, a small dependency set, and no install-time scripts or workflow hazards. Its only release was over five years ago, and the proprietary license provides limited transparency for an open-source dependency.
38%
Total Score
50
100
50
83
The manifest declares a proprietary license, with no detected license text or license file in either the package or repository; this creates a significant transparency and reuse concern.
There has been only one release, published over five years ago, with no releases in the last 12 months; this is strong evidence of abandonment risk.
The repository is owned by an individual user rather than an organization, and no stronger project backing is shown to compensate for the thin maintenance record.
The repository has no stars or forks and only one watcher; popularity is supporting evidence rather than decisive, but this offers little evidence of broad project adoption.
The repository is not archived, which is a limited positive, but its last push was over five years ago and does not offset the stale release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.