The package includes a clear README and MIT license, with no install-time scripts. The single maintainer, absent security policy, and lack of security scanning leave limited ongoing oversight.
58%
Total Score
50
100
83
75
The package has had no release in more than six years, with zero releases in the last 12 months. Its five-release history shows some maturity, but the long publication gap raises maintenance concerns.
The repository had no commits and no active maintainers in the last three months. This indicates limited recent maintenance activity, even though the repository is not archived.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tools are configured. That leaves dependency and repository security checks less visible.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.