Healthy and reasonable to adopt, with a young project and a single active contributor as the main concerns. The organization-backed repository is maintained, tested, non-deprecated, and uses read-only workflow permissions without dangerous workflow patterns.
78%
Total Score
75
100
89
90
One contributor made all four commits in the last three months. Organization ownership provides some handoff capacity, but no second active contributor is visible, leaving a real continuity risk.
Four commits in the last three months show recent work, but activity is still limited and concentrated during the package's short history.
The repository has zero stars, forks, and watchers. This does not establish a defect, but it provides no community adoption or external review cushion for this very young package.
Composer build tooling is present, but no security scanning tools are reported. That is a modest repository hygiene gap rather than evidence of abandonment.
No security policy is present. For a young package this weakens vulnerability-reporting transparency, although it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
componenta/arrayable Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.