Healthy and suitable to use, with a concentrated maintainer base to watch. The repository is actively maintained, releases are documented, and the package has tests, a clear license, and no deprecation or workflow-risk findings; recent commits all come from one contributor and no security policy is published.
78%
Total Score
88
100
94
75
All 67 recent commits came from one contributor, creating a real continuity risk. Organization backing provides some handoff capacity, but no second recent contributor is shown.
The project uses Composer and Phing build tooling, which supports repeatable builds, but no security scanning tools were detected.
The repository has no published security policy, leaving vulnerability-reporting expectations less transparent for users of this extension.
One workflow lacks top-level token permissions and another declares write access, which is weaker workflow permission hygiene than explicitly limiting tokens to read-only access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.