The repository has a changelog, release notes, and Dependabot, but recent maintenance is absent. Workflow reuse of inherited secrets and unpinned actions add avoidable upkeep risk; organizational ownership and a stable dependency profile help.
60%
Total Score
75
100
94
50
The package has existed since 2017 but has only six releases, with no registry release in more than two years. That is a meaningful sign of slowing maintenance for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This raises abandonment risk despite the package's established history.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a modest concern for a mature package, not evidence that the package is unsafe.
All three analyzed action references are unpinned, and a high-confidence medium-severity secrets-inherit finding affects the release workflow. There are no untrusted checkouts or script-injection findings, so this is avoidable hygiene risk rather than a severe workflow threat.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.