Healthy and reasonable to use, with some project-maturity caveats. It has a clear README, tests, stable licensing, safe release automation, and active organization backing, but the project is young and all recent commits come from one contributor with no security policy.
78%
Total Score
75
100
83
90
The package is only 92 days old with two releases about 61 days apart, so maintenance history is still limited but does not show abandonment.
All three recent commits came from one contributor, creating a real continuity risk; organization ownership provides some ability to hand maintenance off but no second active contributor is shown.
Three commits were made in the last three months by one active maintainer, showing recent work but limited maintenance capacity.
The repository has zero stars, forks, and watchers, offering no adoption evidence; the organization backing and coherent repository compensate for this weak supporting signal.
Composer build tooling is present, but no security-scanning tools are configured, leaving a modest transparency and assurance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
psr/http-message Version ^2.0 | — | — |
componenta/config Version ^1.0 || ^2.0.2 | — | — |
componenta/mimetype-detector Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.