The repository is compact and includes tests, while the package has no install scripts or deprecation notice. Missing security scanning and a security policy leave less transparency for future changes.
60%
Total Score
50
100
81
75
Only one registry publisher is listed, leaving limited publishing redundancy. The linked repository is also owned by an individual, so no organizational backing compensates for the thin maintainer base.
The package has only 3 releases across about 4 years and no releases in the last 12 months, indicating a slow maintenance cadence for a dependency.
The repository had no commits and no active maintainers in the last 3 months, consistent with the long release gap and raising abandonment concern.
Composer is used as a build tool, which fits this PHP package, but no security scanning tools were detected. The missing scanning reduces development transparency without making the package unfit by itself.
No security policy was found in the repository, leaving no documented path for reporting vulnerabilities or handling security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
phpstan/phpstan Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.