The six-file artifact offers little consumer guidance, with no README, tests, or changelog. Composer is present, but no security scanning or security policy is reported; the repository itself is not archived or deprecated.
39%
Total Score
0
100
69
83
The last release was in October 2016, with no releases in the past 12 months and only five releases overall. This is strong evidence of abandonment risk for a current dependency.
The repository had zero commits and zero active maintainers in the last three months, consistent with its last push nearly 10 years ago. This materially increases abandonment risk.
No license is declared, detected, or included in the package or repository. That leaves the legal terms for using this dependency unclear.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but a missing README reduces transparency for a small library package.
Composer build tooling is present, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sanatorium/path-installers Version >=1.0.0 | — | — |
cartalyst/composer-installers Version >=1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.