The package includes a consumer README and a small, apparently focused dependency set. It has no license or security policy, leaving important adoption and maintenance details undocumented.
8%
Total Score
50
42
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the release.
Only two releases exist, both from December 2017, with no releases in the last 12 months. The roughly 8 years 9 months since the latest release creates substantial abandonment risk.
The linked repository is archived, and its last push was about 8 years 9 months ago. Archived source indicates the project is no longer maintained.
No declared license or license file was found in the package or repository. That creates a real legal and adoption concern for downstream projects.
The repository had no commits and no active maintainers in the last 3 months. This reinforces the evidence of long-term inactivity rather than a merely slow release cadence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 | — | — |
trigur/trigurpackage Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.