The repository is organization-owned, licensed, and has tests, but registry releases have stopped for over a year and recent commit activity is concentrated in one contributor. The package is stable and not deprecated, which reduces—but does not remove—the adoption risk.
45%
Total Score
75
100
75
83
The package is flagged as borrowing the identity of wikimedia/composer-merge-plugin, which has far more downloads; the absence of artifact overlap does not offset the explicit identity signal. Consumers may have intended the established lookalike instead.
There have been no releases in the last 12 months, and the latest registry release was over a year ago. One recent repository commit provides some evidence of activity but does not restore release cadence.
All recent repository commits came from one contributor, creating a thin effective maintainer base. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only one commit was recorded in the last three months, indicating limited recent maintenance even though the repository was updated recently.
Composer build tooling is present, but no security scanning tools were detected. For this small PHP utility, the missing scanning is a hygiene gap rather than a severe health concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^5 || ^6 || ^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.