The Apache-2.0 license, substantial README, release notes, and organization-backed repository make the package transparent and straightforward to evaluate. Pin this release and watch for renewed commit activity.
68%
Total Score
75
100
88
75
The package has existed for about 3 years with 20 releases, but only 2 releases in the last 12 months. The release published today provides some evidence of ongoing maintenance, though the recent cadence is modest.
There were 0 commits and 0 active maintainers in the last 3 months. A release published today partly offsets this, but the absence of recent commit activity leaves maintenance continuity uncertain.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest repository hygiene gap rather than evidence of abandonment.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it does not by itself show that the package is unsafe to depend on.
Both workflows were fully analyzed with no high- or medium-confidence audit findings and no untrusted checkout or script-injection paths. However, all 7 action references are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^6.0 || ^7.0 | — | — |
league/flysystem Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.