Recent releases and 23 commits in the last three months show ongoing maintenance, while the stable v6.0.2 release includes a README, tests, and release notes. The 32 runtime dependencies and lack of security policy or scanning increase upkeep and review burden.
70%
Total Score
67
50
94
75
The package declares 32 runtime dependencies, including several infrastructure, cloud, messaging, and HTTP components. This broad dependency surface increases maintenance and transitive supply-chain burden.
The repository is owned by a user account rather than an organization, so the single-maintainer concentration is not visibly compensated by organizational backing.
All 23 commits in the last three months came from one contributor, giving the project a concentrated maintenance dependency and limited handoff resilience.
Composer build tooling is present, but no security-scanning tools were detected. That leaves dependency and build-risk review less automated.
The repository has no security policy. This is a transparency and vulnerability-reporting gap for a library covering databases, queues, authentication, encryption, and cloud integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/clock Version * | — | — |
nyholm/psr7 Version ^1.1 | — | — |
ramsey/uuid Version ^4.0 | — | — |
tbachert/spi Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.