The published artifact is extremely minimal, with only two files and no consumer documentation. Organization ownership and a single runtime dependency provide some context, but do not offset the lack of ongoing maintenance.
10%
Total Score
50
40
50
Packagist marks the entire package as abandoned, with no replacement provided. Package-level deprecation is a severe adoption risk regardless of the repository's unarchived status.
The package has only two releases, both published on October 30, 2013, and none in the last 12 months. This indicates more than 12 years without a release update.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release inactivity. No newer maintenance evidence compensates for this.
The release contains only composer.json and composer.php, leaving little evidence of documentation, validation, or broader project structure. Its small size may fit a simple loader, but it reinforces the limited transparency of this release.
The artifact has no README, tests, or changelog. Missing tests and a changelog are normal in published artifacts, but the absent README is a real documentation gap for a package consumers must integrate.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.