Experimental helper for vendor directory location in Composer
45%
Total Score
25
100
78
75
The package has only two releases, both dating from 2014, with no release in roughly 12 years. This is strong evidence of abandonment risk, although the package's small scope may reduce the need for frequent changes.
There were zero commits and zero active maintainers in the last three months, consistent with no observed activity since 2014. This materially increases abandonment and compatibility risk.
The repository is owned by an individual account rather than an organization, so the single registry maintainer is consistent with the available project backing. This provides limited maintenance redundancy.
The repository has five stars and no forks, indicating limited adoption and external validation. Popularity is supporting evidence rather than decisive, but it provides little compensating confidence for the maintenance gap.
The repository uses Composer but has no detected security-scanning tools. Composer is appropriate for the package; the missing scanning is a minor transparency gap rather than a severe concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.