The repository is tiny and has no security policy, while its README and stable version provide only modest reassurance. Pinning this release leaves little evidence of ongoing support.
42%
Total Score
64
75
This is the package's only release, published over five years ago, with no releases in the last 12 months. The absence of an archive flag does not offset the strong evidence of abandonment risk.
The manifest declares a proprietary license, so the release is licensed; no license file or detected repository license provides less transparency about the applicable terms.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of community adoption or review.
Composer is used for builds, which fits the package, but no security-scanning tooling is present. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The repository has no security policy. For a package that is installed into an application, this leaves vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.