Version 9.3.1 appears to be a healthy, mature release suitable for dependency use. The package has been maintained since 2018 with 159 releases, 31 releases in the last 12 months, and a stable non-prerelease version. Its linked Automattic-owned repository is active rather than archived, shows substantial recent commit and pull-request activity, includes tests and a changelog even though those are not packaged, and has Composer, Dependabot, CodeQL, and a security policy. The main concern is concentrated recent commit activity: one contributor made about 84% of the last three months' commits, although 12 active contributors and organizational backing materially reduce the bus-factor risk. Workflow permissions are also not explicitly constrained at the top level, but no top-level write permissions or untrusted checkouts were detected.
88%
Total Score
90
100
90
One contributor accounts for about 84% of recent commits, creating concentration risk; however, 12 contributors were active and the repository is organization-owned, so this is a caution rather than a severe abandonment concern.
All 10 workflows lack top-level permissions declarations, which weakens least-privilege transparency; nevertheless, no workflow has top-level write permissions and only two rely on job-level permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.