Its MIT license, tests, and small runtime dependency surface keep integration straightforward. The alpha release, no commits in three months, absent security scanning, and unpinned workflow actions warrant caution for production use.
60%
Total Score
75
100
81
67
The repository recorded zero commits and zero active maintainers in the last three months. Recent release activity partly compensates, but the lack of current development activity raises maintenance risk.
The repository name does not match the package name and its README does not mention the package, so the link may not clearly establish package ownership. The mismatch is a transparency concern despite the organization backing.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance hygiene gap rather than evidence of maliciousness.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
This release is an alpha prerelease, so its API and behavior may still change even though it is the current major-version line.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.