The package is small, tested, licensed, and clearly tied to its source repository. Its single-maintainer project has had no releases or commits for about four years, making future fixes uncertain.
57%
Total Score
25
100
78
83
Only three releases were published, with the latest on March 5, 2022 and none in the last 12 months. This long pause materially raises abandonment risk for a dependency.
There were zero commits and zero active maintainers in the last three months, consistent with repository activity having stopped around four years ago.
Only one registry publishing account is listed, and the project backing is an individual rather than an organization. This leaves limited visible publishing capacity if that maintainer stops supporting it.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide no external sign of an active community.
Composer build tooling is present, but no security scanning tool was detected. For this small package that is a modest hygiene gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version 1.1.1|2.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.