The package is documented, licensed, tested in its repository, and backed by an organization. Maintenance has slowed, and workflow credential and permission hygiene needs attention.
65%
Total Score
75
93
67
The package has 10 releases over 520 days, but only one release in the last 12 months; this suggests a meaningful slowdown for a maintained library.
The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete maintenance concern despite the recent release and push history.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a library dependency.
All three workflows use top-level write permissions, all three action references are unpinned, and each inherits secrets in a reusable workflow; the audit found these issues with high confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^7.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
fast-forward/config Version ^1.1 | — | — |
container-interop/service-provider Version ^0.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.