Usable with caveats: the package is mature, clearly backed, licensed, tested in its repository, and has strong security and build hygiene. However, this release is old and there have been no registry releases or commits in the measured recent periods, so verify that it still fits your PHP project before adopting it.
68%
Total Score
75
100
94
88
The project has existed since 2012 with 35 releases, but it recorded no registry releases in the last 12 months and this release is therefore not recent. The long history is reassuring, while the recent release gap lowers confidence in ongoing delivery.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful recent-maintenance concern. The recent repository push and open pull requests provide some counterevidence but do not show completed code changes.
There are 24 open pull requests and two new pull requests in the last month, but no issues were closed and no pull requests were merged in that period. This suggests some ongoing attention without demonstrated recent integration.
All seven workflows omit top-level token permissions, and none explicitly declare read-only permissions. Although no workflow requests top-level write access, the lack of explicit least-privilege declarations is a security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
symfony/deprecation-contracts Version ^2.2 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.