Healthy and reasonable to adopt, with some maintenance caveats. It has recent releases, a stable version, tests, clear packaging, and active organization backing; the main concern is that all four recent commits came from one contributor and no security policy is present.
78%
Total Score
75
50
83
90
Nine runtime dependencies are declared, including framework and PSR components. This is a meaningful dependency surface for an error-handling library, but it is explicit rather than unusually opaque.
The package is young at 89 days old but has four releases, including one within the latest collection period, with a median interval of about 28 days. This shows ongoing release activity but not yet long-term maturity.
One contributor made all four commits in the last three months, creating a real continuity risk. Organization ownership provides some ability to hand maintenance off, so this is caution rather than severe risk.
There were four commits in the last three months, showing recent activity, but all activity came from one active maintainer.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity is not decisive and the package has stronger evidence from its tests, releases, and organization backing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^2.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.