The MIT license, focused dependency set, matching repository, and release notes make adoption straightforward. Recent releases support ongoing maintenance, though no commits were recorded in the last three months and workflow dependencies are unpinned.
78%
Total Score
75
100
93
75
No commits or active maintainers were recorded in the last three months. Recent releases partly offset this quiet period, but it remains a modest maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it does not by itself indicate that the package is unsafe to depend on.
Both workflows were analyzed cleanly with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all 3 analyzed action references are unpinned, which leaves workflow supply-chain versions less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.