Its ten-character README offers almost no integration guidance, and no security policy or scanning is provided. The package matches its repository, but the project shows no activity to support continued maintenance.
8%
Total Score
0
25
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the package.
The package has had no release in more than nine years, despite five releases in 2017. This strongly indicates that maintenance has stopped.
There were no commits and no active maintainers in the last three months, consistent with the repository having been inactive for years. This reinforces the abandonment concern.
The linked repository is archived, and its last push was in July 2017. Archived source is a severe abandonment risk for a dependency.
No license is declared, and no license file was detected in either the package or repository. That leaves the release without clear permission for downstream use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.