The repository is licensed and has recent commits under organization backing. Documentation and security-process evidence are thin, and the single-contributor bus factor limits resilience.
58%
Total Score
83
100
75
75
The artifact lacks a README, which is a meaningful documentation gap for a library consumers must integrate against; absent tests and changelog files are normal for published artifacts and do not add concern here.
This is a young package at 41 days old with only one release, so there is little evidence of release consistency or long-term maintenance.
All 17 recent commits came from one contributor, concentrating maintenance responsibility and increasing continuity risk even with organization ownership.
Composer is used for builds, but no security scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented process for reporting vulnerabilities or understanding security maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1.1 || ^2.0.1 | — | — |
psr/simple-cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.