The package is licensed, documented, tested in the repository, and supported by security tooling. Install-time scripts and an unpinned workflow image add modest operational risk, while ongoing release and commit activity remains limited.
62%
Total Score
50
100
94
67
post-install-cmd and post-update-cmd scripts run during Composer operations, adding execution-time supply-chain exposure for consumers.
The package has only 3 releases, with none in the last 12 months; its latest registry release was about 5 years ago. This is a meaningful maintenance concern, although the repository is not archived.
There were 0 commits and 0 active maintainers in the last 3 months. A recent repository push is compensating evidence, but it does not demonstrate sustained development activity.
All 3 workflows were analyzed with no untrusted checkouts or script injection, but all 9 action references are unpinned and the audit found a high-confidence unpinned container image. This is a workflow hygiene concern, not a severe dependency verdict by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.