The package has had no release since March 2019 and no recent commit activity, while its only version remains an alpha. It has a clear MIT license, tests in the repository, and no install-time scripts, but the maintenance gap makes long-term reliance risky.
42%
Total Score
0
100
70
75
This package has only one release, published in March 2019, with no releases in the last 12 months. That long release gap materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. Although the repository was pushed in September 2022, current development activity is absent.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though the package's small scope and other signals partly limit its impact.
The latest and only release is 1.0.0-alpha1, so consumers are depending on explicitly unfinished software with no later stable release to demonstrate maturity.
The workflow has read-only permissions and no detected high-confidence audit findings, but all three referenced actions are unpinned, leaving build inputs less reproducible than they could be.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.