It includes tests, release notes, a clear MIT license, and useful README guidance. Organization ownership and recent publishing provide some continuity, but the project lacks a security policy.
67%
Total Score
83
88
83
Six releases in 41 days show active publishing, but the short history provides limited evidence of long-term maintenance.
One contributor made all 10 recent commits, creating a meaningful continuity risk; organization ownership offers some ability to hand off maintenance but no second active contributor is shown.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest assurance gap.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
The only workflow uses read-only permissions and has no untrusted sinks or audit findings, but all three analyzed action references are unpinned, weakening build reproducibility and trust in workflow dependencies.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
componenta/di Version ^5.0.3 | — | — |
psr/container Version ^2.0 | — | — |
componenta/app Version ^5.0.0 | — | — |
componenta/scope Version ^1.0 | — | — |
psr/http-factory Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.