The project has no security scanning and almost no community activity. Its small seven-file footprint and clear README keep adoption understandable, but there is no recent maintenance evidence.
42%
Total Score
50
100
75
75
This package has only one release, published over five years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, although the repository is not archived.
The source repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it offers no organizational backing to offset the thin maintenance evidence.
The repository has no open issues or pull requests and recorded no issue or pull-request activity recently. This provides no evidence of an active support or maintenance community.
The repository has zero stars and forks and only one watcher. Popularity is not decisive for a small package, but these numbers provide little supporting evidence of adoption or review.
Composer is used for builds, which is appropriate for this package, but no security-scanning tooling is present. The missing scanning reduces assurance for a dependency with no recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.