Risky to adopt: the package is licensed and clearly structured, but it has had no release or repository activity for over four years. Its small audience and lack of security policy add maintenance and transparency concerns.
40%
Total Score
50
100
72
75
There has been only one release, published over four years ago, with no releases in the last 12 months. This is strong evidence of limited ongoing maintenance, although the module is small and stable.
There were no commits and no active maintainers during the last three months, reinforcing the risk that defects or compatibility problems may go unaddressed.
One issue remains open and there has been no issue or pull-request activity in the last month, consistent with a project that is not actively maintained.
The repository has zero stars and forks and only three watchers. This is supporting evidence of a very small user base, though popularity alone is not decisive for a narrowly scoped module.
Composer is used for builds, but no security scanning tooling is present. That is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.