The package includes a clear MIT license, tests, documentation, and a small dependency set. Its maintenance has stopped, with no releases or repository commits for nearly seven years, and the repository has no security policy or scanning tools.
58%
Total Score
50
100
79
67
Only two releases were published, with the latest in October 2019 and none in nearly seven years. That long period without updates is a meaningful maintenance and abandonment concern.
There were no commits and no active maintainers in the three months measured. Combined with the last push in October 2019, this indicates sustained inactivity.
Composer is used for the build, but no security scanning tools are configured. This is a transparency and maintenance gap, though it is not severe by itself.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented.
Version 0.1.0 is not a stable major release, so the API may be less mature or more subject to breaking changes. The package does provide tests and documentation, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.