The project has a clear license, useful documentation, and a small runtime footprint. Its long inactivity and lack of a security policy reduce confidence in future fixes.
52%
Total Score
50
100
81
83
The latest release was 7 years ago, with no releases in the last 12 months. This is a meaningful maintenance concern, although the package appears intentionally small and stable.
There were no commits and no active maintainers in the last 3 months, consistent with the long gap since the latest release and indicating limited current maintenance capacity.
There are no open issues or pull requests and no recent issue or pull-request activity. For a tiny, stable plugin this is not abandonment proof, but it provides little evidence of active support.
The repository uses Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe dependency risk.
No repository security policy was found. That weakens the project's documented process for handling vulnerabilities, especially given the absence of recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.