Usable with caveats: the package is licensed, documented, and backed by a matching repository, but it has had no release in nearly seven years and no commits in the last three months. Its small, inactive project footprint and lack of security policy make it a maintenance risk for new dependencies.
58%
Total Score
50
100
78
75
A 2,816-character README explains installation and usage, which supports consumers. The artifact and repository contain no tests or changelog, reducing transparency somewhat, though tests and changelogs are not expected in published artifacts.
The repository is owned by an individual rather than an organization, so there is no visible organizational support to compensate for the limited recent activity.
The package has only four releases and none in the last 12 months; the latest release was in June 2019. This is a substantial maintenance concern for a package intended as an application dependency.
There were zero commits and zero active maintainers in the last three months, consistent with a project that is no longer actively maintained.
The repository has zero stars, forks, and watchers, providing no supporting evidence of broad review or community use. Popularity is only supporting evidence, so this is a modest concern rather than a decisive risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.