Clear installation guidance, a matching repository, and a documented release make adoption straightforward. MIT licensing and organization ownership add transparency, but the project lacks recent maintenance and visible security safeguards.
40%
Total Score
67
100
81
67
There were no commits and no active maintainers in the last 3 months, consistent with roughly 7 years since the last push. This is the strongest evidence of abandonment risk.
A post-install Composer script adds install-time behavior that consumers must trust. No provided signal explains or compensates for that behavior, so it is a modest supply-chain hygiene concern.
This is the package's only release, published about 9 years ago, with no releases in the last 12 months. That strongly raises abandonment risk despite the stable version label.
Composer build tooling is present, but no security-scanning tools are configured. That weakens maintenance and release oversight for an old plugin.
The repository is not archived, which is positive, but it was last pushed about 7 years ago. The inactivity is a maintenance concern, also reflected in the commit activity signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
uconn/banner Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.