Usable with caveats: it is actively released and backed by an unarchived organization repository, but all recent commits come from one contributor and the project has no security policy or scanning. Review its install scripts before adopting it.
72%
Total Score
75
100
83
80
The package defines post-install and post-update Composer scripts. These are not inherently unsafe, but they add install-time behavior that should be reviewed before allowing automated dependency installation.
One contributor made all 6 commits in the last 3 months, creating a genuine continuity risk. Organization backing provides some capacity for handoff, but no second active contributor is shown.
No new or closed issues or pull requests were recorded in the last month, while the total issue and pull-request counts are unavailable. This provides little evidence of community support but does not establish abandonment.
The repository has 3 stars, 0 forks, and 1 watcher. This indicates limited adoption, but popularity is supporting evidence only and does not outweigh the active release history and recent commits.
Composer is used for builds, but no security scanning tool is configured. The build tooling is appropriate, while the missing automated security checks reduce assurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.