Usable with caveats: it is actively released, tested, licensed, and backed by an organization, but the project is only 84 days old and all recent commits come from one contributor. Zero repository popularity and no security policy add transparency concerns.
72%
Total Score
83
100
83
90
The package is young at 84 days, with 9 releases and a recent release, so it shows active delivery but has limited time to demonstrate maturity.
All 127 recent commits came from one contributor, creating a genuine continuity risk. Organization backing helps provide ownership context, but no second active contributor is shown.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no external adoption signal for a very young package.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap.
The repository has no security policy, so the process for reporting and coordinating vulnerability fixes is not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
componenta/di Version ^5.0.0 | — | — |
psr/container Version ^2.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
componenta/reflection Version ^2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.