Usable with caveats: the package is actively released and backed by a repository with strong testing and security hygiene, but Packagist marks this package deprecated. Recent work is concentrated entirely in one contributor, increasing continuity risk despite organization backing.
58%
Total Score
75
100
83
90
Packagist marks the package deprecated at package scope, with no clear deprecation message; this is a significant adoption and continuity concern even though the listed replacement is the same package.
One contributor made 100% of the 390 recent commits. Organization ownership provides some handoff capacity, but no second active contributor is evidenced, so bus-factor risk remains.
There were 390 commits in the last 3 months, showing exceptionally active development, but all activity came from one maintainer, leaving continuity dependent on that person.
The repository has 13 stars and no forks, providing limited external adoption evidence; popularity is supporting evidence only and does not outweigh the strong release and activity signals.
Both workflows lack top-level permissions declarations and rely on job-level permissions, which is less explicit than a repository-wide least-privilege default.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.