This is a clearly licensed, non-deprecated, organization-backed package with a small and understandable Composer dependency profile, no install-time lifecycle scripts, and a source repository that is not archived. However, it is extremely new: only two releases exist over roughly 23 hours, so there is little evidence of sustained maintenance or production maturity. The repository has no tests, changelog, security policy, security scanning, or observable commit activity yet, and it has no popularity or issue activity. The package may be usable, but adopting it carries meaningful maturity and long-term maintenance uncertainty; reassess after a longer maintenance history and stronger project hygiene are visible.
64%
Total Score
88
100
72
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.