The package is clearly documented, tested, licensed, and has a small dependency surface. Its maintenance record is too new to establish long-term reliability, and workflow dependencies are not pinned; add a security policy as the project matures.
68%
Total Score
50
100
83
50
This is the first release, published today, so there is no release history or cadence to demonstrate sustained maintenance. The repository is present and recently pushed, which is consistent with a newly launched project rather than abandonment.
There were no commits or active maintainers in the measured three-month window, but the package itself was released today and the repository was pushed recently. This is an unproven maintenance record rather than clear abandonment.
Composer build tooling is present, but no security scanning tool was detected. For a new package this is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy, leaving no documented process for reporting vulnerabilities. This lowers transparency, though the package's small scope and clear documentation partly offset the gap.
The sole workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but both of its two action references are unpinned. That creates avoidable supply-chain drift risk in CI.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.