Usable with caveats: the package is licensed, documented, stable, and backed by a matching organization repository, but it has had no release or commit activity for about five years. Treat it as a maintenance-risk dependency and verify compatibility with current WinterCMS versions.
58%
Total Score
50
100
81
83
There were no commits and no active maintainers in the last three months. Combined with the last push being about five years ago, this is strong evidence of inactive maintenance.
The latest release was published about five years ago, with no releases in the last 12 months. This materially lowers confidence that compatibility issues are being addressed.
The repository uses Composer, but has no security-scanning tools. For a small, inactive plugin this is a transparency and upkeep gap, though it is not by itself evidence of unsafe behavior.
The repository is not archived, but its last push was about five years ago, reinforcing the maintenance concern shown by the release history.
No security policy is present. This makes vulnerability reporting less transparent, although the small project scope and lack of reported issue backlog provide limited compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.