Only one contributor has committed in the last three months, and the repository has no security scanning. A README, tests, organization backing, and read-only workflow permissions provide useful safeguards.
68%
Total Score
67
88
67
The package is only 95 days old with two releases and a roughly 60-day median interval, so its maintenance record is still limited rather than established.
One contributor holds 100% of recent commits, creating concentration risk, although organization ownership provides some ability to hand off maintenance.
Only three commits were made in the last three months, all by one active maintainer; this shows recent activity but limited maintenance capacity.
Composer build tooling is present, but no security scanning tool was detected, leaving a repository hygiene gap.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
componenta/app Version ^1.0 || ^2.0 || ^3.0.2 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
componenta/config Version ^1.0 || ^2.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.