Clear documentation, tests, and a permissive license support integration. The package is still young, so its longer-term stability is not yet well established.
72%
Total Score
83
94
75
All nine recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and review gap.
The repository has no security policy, so users lack a documented channel and process for reporting vulnerabilities.
The workflow has read-only permissions and no audited dangerous findings, but all 3 of 3 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
componenta/app Version ^4.0.0 || ^5.0.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
componenta/http-emitter Version ^1.0.3 | — | — |
componenta/error-handler Version ^1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.