This is a healthy, actively maintained release with a six-year history, 48 releases, six releases in the last 12 months, a stable non-prerelease version, and no registry deprecation. The linked repository is active and unarchived, has tests, changelog, build tooling, Dependabot scanning, and recent activity from four contributors, although commit ownership is concentrated in one contributor and there is no security policy. Install-time Composer lifecycle scripts and several workflows with write permissions warrant review in a deployment-sensitive environment, but the package's strong release cadence, repository transparency, licensing, and current maintenance substantially outweigh these concerns.
87%
Total Score
70
100
100
70
The package defines post-install-cmd and post-update-cmd scripts, which add install-time execution and deserve review before adoption. Their presence is a supply-chain and reproducibility consideration, but not by itself evidence of abandonment.
Only one account has registry publish access, which creates publishing continuity risk. However, registry access reflects authorization rather than actual maintenance, and the repository shows four active contributors recently.
The repository owner is an individual user rather than an organization, so the concentrated contributor activity and single registry maintainer are not offset by explicit organizational backing.
Commit activity is concentrated in the top contributor at 83.3% (30 of 36 commits), creating a genuine continuity concern. This is partly mitigated by three additional contributors remaining active during the same period.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. The presence of Dependabot provides some compensation but does not replace a policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^6.4 | — | — |
composer/installers Version ~2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.