38%
Total Score
unhealthy
Risky: no release or repository activity for over 9 years, with only three releases made in one brief burst.
Only three releases were published, all clustered on the same day in April 2017, and there have been no releases in over 9 years. This gives little evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the last push occurring in 2017. The long inactivity materially raises abandonment risk.
The package declares post-install and post-update Composer scripts. These hooks add installation-time behavior that consumers must account for, although their presence alone does not show harmful behavior.
The repository is not marked archived, but its last push was in April 2017, so the non-archived status does not offset the observed inactivity.
The linked repository has no security policy. For an old package with no recent activity, this leaves vulnerability reporting and maintenance expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.