The role is small, clearly documented, MIT-licensed, and has no install-time scripts or meaningful dependency burden. Its latest release and repository update were about 9 years ago, with no recent issue activity or security policy, so maintenance risk is substantial.
42%
Total Score
50
100
64
75
The package has had only 3 releases, and none in the last 12 months; its latest release was about 9 years ago. This is strong evidence of abandonment risk for a dependency.
There are no open issues or pull requests and no activity in the last month. While a small stable role may receive little discussion, this provides no evidence of active maintenance alongside the old release history.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these counters provide little indication of a maintained or widely exercised project.
Composer is used as a build tool, but no security scanning tools are configured. That is a modest hygiene gap rather than a severe risk for this small Ansible role.
The repository is not archived, which is a compensating sign, but it was last pushed about 9 years ago. Its unarchived status does not offset the long period without updates.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.