Documentation, tests, and a matching license provide a solid foundation, while recent commits show the project is active. The repository lacks security scanning and policy, and its workflows use unpinned actions with one broad write permission.
67%
Total Score
83
50
88
50
The package declares 11 runtime dependencies, including several related Oihana components and Somnambulist Validation. This is a meaningful dependency surface but is coherent with a feature-rich validation library.
post-install-cmd and post-update-cmd scripts run during Composer operations. These add supply-chain exposure and deserve review, although the signal does not show that they are malicious.
This is a young package, released once 90 days ago with no subsequent release. That limited history makes long-term maintenance less proven.
All seven recent commits came from one contributor, leaving maintenance concentrated in a single person. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a modest transparency and maintenance gap rather than evidence of compromise.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
oihana/php-core Version dev-main | — | — |
oihana/php-enums Version dev-main | — | — |
oihana/php-models Version dev-main | — | — |
oihana/php-schema Version dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.