The package is clearly licensed and includes a consumer README. Its only release was over six years ago, with no recent issues or pull requests and a repository showing no meaningful adoption, leaving maintenance risk high.
38%
Total Score
50
100
72
83
The package has only one recorded release, on May 12, 2020, and none in the last 12 months. This is strong evidence that maintenance has stopped for a package released over six years ago.
The linked repository is owned by an individual account rather than an organization. This does not prove abandonment, but it provides less visible project backing alongside the inactive repository.
There are no open issues or pull requests and no issue or pull-request activity in the last month. While a quiet issue tracker can be healthy for a mature package, here it reinforces the long release gap.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no evidence of an active user or contributor community.
Composer is used as the build tool, but no security-scanning tooling is present. The established build tool is positive, while the missing scanner is a modest hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
snanword/think_installer Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.