The README clearly explains the package’s caching API and the dependency surface is small. Its maintenance record is too thin for a dependable long-term dependency, while the proprietary license may restrict reuse.
42%
Total Score
50
100
60
75
This is the only release, published about five years ago, with no releases in the last 12 months. That strongly raises abandonment risk despite the stable version.
The manifest declares a proprietary license, so the release is licensed, but the absence of a license file gives consumers less transparency and may restrict redistribution or modification.
Only one registry account has publish access. This is a thin publishing base, and the available project context does not show organizational backing to compensate for it.
The repository is not archived, which preserves a path for future maintenance, but its last push was about five years ago and does not offset the inactive release history.
The linked repository has no security policy. This is a modest transparency gap for a package that may be deployed in applications, though it is less significant than the long maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.