Usable with caveats: the package is actively published, tested, clearly licensed, and backed by a matching organization repository. It is still young, has only one active contributor, and lacks a security policy and automated security scanning.
72%
Total Score
67
100
81
90
The package is only 89 days old with four releases, including a release within the last day, showing active early maintenance but limited track record.
One contributor made all four commits in the last three months, creating a real continuity risk. Organization ownership provides some ability to hand off maintenance but does not remove the current concentration.
Four commits were made in the last three months, so development is active, though all activity comes from only one maintainer.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but the package is very young and popularity alone does not establish a health failure.
Composer is used as the build tool, but no security scanning tools are configured, leaving a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.