The project has stopped releasing and committing, with no activity in the past year. Clear documentation, tests, licensing, and a matching source repository reduce adoption risk, but the small project has no security scanning or policy.
58%
Total Score
50
50
69
88
There were zero commits and zero active maintainers in the last three months, consistent with a project whose maintenance has gone quiet.
Four runtime dependencies, including Composer itself and the plugin API, create a meaningful compatibility surface for a Composer plugin but do not indicate excessive dependency burden.
The package is 429 days old with 23 releases, but none in the last 12 months; its rapid initial release burst has not continued.
There are no open issues, but one pull request remains open and there has been no issue or pull-request activity in the last month.
The repository has one star and no forks or watchers, providing little evidence of broad community use or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/composer Version ^2.0 | — | — |
sonrac/composer-authenticated-repository-plugin Version ^0.2.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.