Clear documentation, a matching repository, tests, and an MIT license support adoption. Unpinned workflow actions and the lack of a security policy leave modest process gaps.
62%
Total Score
50
100
86
67
The repository is owned by an individual account rather than an organization, so the single-contributor maintenance concentration has no shown organizational backing to offset it.
This is a young package with one release, published 43 days ago, so there is not yet enough release history to demonstrate sustained maintenance.
One contributor made all recent commits, leaving no demonstrated contributor redundancy. The repository is user-owned, so no organizational handoff evidence compensates for that concentration.
There was one commit in the last three months from one active maintainer. The recent activity is positive, but the very small amount of activity provides limited evidence of ongoing maintenance.
Composer build tooling is used, but no security scanning tool was detected. This is a modest process gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.