The MIT license, release notes, repository tests, and security tooling make the project straightforward to inspect. Organization backing helps offset the single-contributor maintenance risk, but install scripts and unpinned workflow actions warrant scrutiny.
68%
Total Score
83
88
50
post-install-cmd and post-update-cmd scripts execute during Composer operations, adding review and supply-chain exposure even though no harmful behavior is shown here.
This is a young package, only 42 days old with one release and no established release interval, so long-term maintenance is not yet demonstrated.
One contributor made all 11 recent commits, leaving a thin maintenance base; organization ownership provides some handoff capacity but does not remove the concentration risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.1.0 is an early, non-stable-major release, so compatibility and maintenance expectations are less established than for a mature major version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ray/di Version ^2.23.0 | — | — |
ray/aop Version ^2.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.