A stable six-year project has organizational backing, matching source, repository tests, and release notes for this version. Licensing, a security policy, and no install-time scripts add useful transparency.
68%
Total Score
75
100
94
83
The repository recorded 0 commits and 0 active maintainers in the last three months, which raises a maintenance concern. The recent 1.16.0 release and repository push show the project is not clearly abandoned, so this is caution rather than danger.
Composer build tooling is present, but no security scanning tools were detected. This is a modest repository hygiene gap, although the separate security policy and clean workflow audit provide some compensation.
All 3 analyzed workflows use unpinned actions, leaving build automation exposed to changing upstream references. The audit found no untrusted checkouts, script injection, dangerous triggers, or high-severity findings, limiting the impact to caution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
webmozart/assert Version ^1.11.0 || ^2.0.0 | — | — |
mezzio/mezzio-router Version ^3.5 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.