The small artifact is easy to inspect, has a clear LGPL-2.1 declaration, and uses only one runtime dependency. Its repository remains identifiable and unarchived, but it offers little evidence of ongoing project support.
42%
Total Score
0
100
81
88
This package has made only one release, on February 28, 2016, with none in the past 12 months; more than 10 years without a release is strong abandonment evidence.
The repository recorded zero commits and zero active maintainers in the past 3 months, consistent with the long period since its only release.
The repository uses Composer, which supports reproducible package building, but has no security-scanning tooling; this is a modest transparency and maintenance gap.
No repository security policy is provided. For a small, inactive package this reduces the available route for reporting issues, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
simplesamlphp/composer-module-installer Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.