This release has strong evidence of active development and reasonable project hygiene: it has a long release history, a stable version, current repository activity, tests, a changelog, licensing, security scanning, and a repository that matches the package. However, the Packagist listing is explicitly marked abandoned and names `lloc/multisite-language-switcher` as its replacement, which is a severe dependency-health concern even though the linked repository is active and the latest release is recent. The repository also has a concentrated commit profile and incomplete workflow/security-policy hardening. Prefer the replacement package rather than adding this abandoned package directly.
30%
Total Score
75
100
88
70
Packagist marks this package as abandoned and provides `lloc/multisite-language-switcher` as a replacement. Active repository and recent release activity mitigate abandonment concerns about the underlying project, but they do not remove the risk of depending on the deprecated package identity.
The package declares `post-install-cmd` and `post-update-cmd` lifecycle scripts. These add install-time execution surface, although the available evidence does not establish that the scripts are unsafe or unusually broad.
The repository owner is a user account rather than an organization, so there is no organizational handoff capacity shown by this signal. The four active contributors provide some practical compensation, but recent commits remain concentrated.
One contributor made 30 of 36 recent commits, or about 83%, while three others contributed the remainder. The additional active contributors provide some coverage, but the high concentration creates a meaningful continuity risk for a user-owned project.
No security policy was found in the repository. This is a transparency gap, though it is partly offset by active maintenance and Dependabot scanning.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^6.4 | — | — |
composer/installers Version ~2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.