The package is small and clearly documented, with repository tests and an active organization behind it. Maintenance is still thin: only one commit in the last three months, one active contributor, and no published security policy.
65%
Total Score
70
100
78
75
Only one registry account has publish access, which is a limited publishing path. The organization-owned repository provides some backing, so this is a caution rather than a severe risk.
The package is 530 days old but has only three releases, with one release in the last 12 months and a median interval of about 239 days. This indicates a slow maintenance cadence rather than abandonment by itself.
All recent commits came from one contributor, creating a concentrated maintenance dependency. Organization ownership offers some handoff capacity but does not remove the current concentration.
Only one commit was recorded in the last three months, from one active maintainer. The recent release and push show activity, but the maintenance pace is thin.
The repository has zero stars and forks and one watcher, so there is little external adoption evidence. Popularity is supporting evidence only and does not outweigh the active organization backing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version * | — | — |
psr/container Version * | — | — |
psr/http-client Version * | — | — |
psr/simple-cache Version * | — | — |
adbario/php-dot-notation Version ^3.3|^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.