The project has a tiny footprint and little consumer documentation. It is not deprecated or archived, and its stable plugin structure keeps the risk from being critical.
42%
Total Score
50
40
50
Only two releases exist, and the latest was published in October 2021; there have been no releases in nearly five years. This is strong evidence of abandonment risk.
The package and repository contain no README, tests, or changelog. The GitHub release for this version is a positive documentation signal, but the lack of consumer documentation and tests still limits transparency.
The repository has no open issues or pull requests and recorded no issue or pull-request activity in the last month. This supports the broader evidence of an inactive project, though a small plugin may naturally have little issue traffic.
The repository has zero stars and forks and only one watcher, providing little evidence of an active user or contributor community. Popularity is supporting evidence rather than a verdict on its own.
Composer is used as a build tool, which is appropriate for this package, but no security-scanning tooling is configured. This is a minor maintenance and assurance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.