Its MIT declaration and small dependency surface are clear, and the repository is not archived. Documentation, tests, security policy, and established development activity are not yet visible.
55%
Total Score
50
100
71
83
One registry maintainer is a thin publishing base for a library, and the project is user-owned rather than organization-backed. This raises continuity risk, though it is not severe by itself.
A missing README is a real documentation gap for a PHP library consumers must integrate with. Missing tests and changelog files are normal in a published artifact and do not lower the assessment here.
The package is less than one day old, with three releases in roughly 7 hours and no longer-term release history. Rapid initial releases are not inherently harmful, but maturity cannot yet be established.
The repository recorded zero commits and zero active maintainers over the last three months. Its same-day push partly reflects the package's newness, but there is no established maintenance record yet.
The repository name does not match the package name, and no README evidence was collected showing that it mentions this package. The source-package relationship is therefore less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/container Version ^2.0 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.