The MIT license, README, and bundled source files make it reasonably transparent. It has no security policy and only two repository stars, so ongoing support is not strongly evidenced.
55%
Total Score
25
100
78
83
The package has made four releases, but none in roughly three years; the latest release was published in July 2023. This materially weakens evidence of ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. Combined with the old last push, this is strong evidence of currently inactive maintenance.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the thin maintenance evidence.
The repository has two stars, one fork, and one watcher. Popularity is only supporting evidence, but these very small numbers provide little independent evidence of community support.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.