Adds extra functionality for interpreting the @dependency annotation
46%
Total Score
unhealthy
Risky: no registry release for nearly five years and no recent repository commits, with the current version still marked alpha.
The latest release was published nearly five years ago, with no releases in the last 12 months. That long gap materially raises abandonment risk despite the package's earlier release history.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the long release gap, this is strong evidence of inactive maintenance.
There were no new or closed issues or pull requests in the last month, while three issues and two pull requests remain open. This supports the broader picture of limited current project activity.
The repository has no security policy. This is a transparency and response-process gap, though it is less serious than the clear maintenance concerns.
The assessed release is v2.1.0-alpha.1, and 63.6% of recent releases were prereleases. Depending on an alpha release adds compatibility and maturity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^6 | — | — |
composer/semver Version ^1|^2|^3 | — | — |
symfony/console Version ^5 | — | — |
nikic/php-parser Version ^4 | — | — |
composer/composer Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.