The repository matches the package, includes a README and changelog, and has no install-time scripts. Its explicit license and organization backing provide useful transparency, but the small user base and single registry publisher limit confidence in continued support.
57%
Total Score
75
79
75
The package has only 5 releases and none in the past five years, with the latest published in June 2021. This is a meaningful sign of possible abandonment, despite the package having an established release history.
There were no commits and no active maintainers in the past three months, consistent with the last push in June 2021. This materially increases the risk that defects or compatibility issues will remain unaddressed.
The repository has 2 stars, 0 forks, and 1 watcher, indicating a very small visible user base. Popularity is only supporting evidence, but this provides little external evidence of ongoing use or support.
The repository has no security policy. For this small configuration package the impact is limited, but the absence reduces transparency about how vulnerabilities would be reported.
Version 0.1.3 is not a stable major release, but it is not marked as a prerelease and recent releases have not been prereleases. This is a modest maturity concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/composer-config-plugin Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.