The package is clearly documented, licensed, and backed by an organization-owned repository. Its small runtime dependency set and absence of install-time scripts are positive, while the missing security policy leaves a modest transparency gap.
61%
Total Score
75
100
88
75
The package has only three releases and none in the last 12 months; its latest release was about 3 years and 6 months ago. This materially raises abandonment risk despite the documented release history.
There were no commits and no active maintainers in the last 3 months, consistent with the long gap since the last release. This is a meaningful maintenance and abandonment concern.
The repository uses Composer, but no security-scanning tools were detected. The build setup is present, while security-monitoring transparency is limited.
No security policy was found in the repository. For a dependency-injection library, this is a genuine but moderate transparency gap.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, its only action reference is unpinned, which leaves a modest reproducibility and workflow supply-chain gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.