The project has a clear license, tests, and an organization-backed repository. Its small dependency surface and matching source tree help offset the maintenance uncertainty.
55%
Total Score
67
100
81
50
The package has 27 releases over roughly 14 years, but it recorded no releases in the last 12 months; the most recent release was on August 15, 2025. This suggests a slowing maintenance cadence.
The repository had zero commits and zero active maintainers in the last three months. Combined with the lack of recent releases, this is a meaningful maintenance concern.
There were no new or closed issues and no merged pull requests in the last month, despite 36 open issues and 5 open pull requests. This indicates limited recent project movement.
Composer is used for the build, but no security scanning tool was detected. The missing scanning is a security-process gap, though it does not by itself show abandonment.
The repository has no security policy. That reduces transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.