The repository includes tests and a changelog, and the package is licensed with a small, focused dependency set. Its release and commit activity has stopped for over a year, while workflow actions are unpinned; pin this version only if that maintenance pause is acceptable.
58%
Total Score
75
100
88
67
The package has made no releases in the last 12 months, despite five releases arriving within roughly one month in 2025. This suggests a sustained maintenance pause after an initially active period.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the release-history evidence of a maintenance pause.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
The workflow audit completed successfully and found no dangerous triggers, sinks, or audit findings. Both analyzed action references are unpinned, which weakens build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/slim Version ^4.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.