The package has no license and the repository does not clearly identify the package. Its tiny dependency set and lack of install scripts reduce exposure, but they do not offset the maintenance and transparency concerns.
35%
Total Score
0
42
50
Only one release exists, published about 7 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with its last push being about 7 years ago. This materially raises abandonment risk.
No declared license, license file, or repository license file was found. That creates a real legal and transparency concern for adoption.
The package has no README, tests, or changelog, although the GitHub release flag provides some release traceability. The missing consumer documentation is still a meaningful gap for a small library.
The repository name does not match the package name, and no README mention was available to establish the repository-package relationship. This weakens provenance transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.