Usable with caveats: it has clear documentation, tests, release notes, and an active-looking repository, but maintenance has been uneven and the pre-1.0 API includes breaking changes.
68%
Total Score
67
100
78
100
The package and repository are owned by the same individual account, which provides direct ownership alignment but also indicates a limited organizational backing structure.
The project has existed since October 2019 with 17 releases, but only one release occurred in the last 12 months, indicating a relatively slow recent cadence despite the current release.
The repository recorded zero commits and zero active maintainers over the last 3 months. Although it was pushed recently and a new release was published, the lack of recent commit activity is a concrete maintenance concern.
The repository has only 2 stars and 1 fork, showing limited external adoption. This is supporting caution rather than a decisive health problem because popularity alone does not establish maintenance quality.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^7.0.7 | — | — |
php-di/invoker Version ^2.2 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.