php dependency injection container
60%
Total Score
caution
No commits in three months, one registry maintainer, and very low repository activity make maintenance capacity uncertain.
The package runs both post-install-cmd and post-update-cmd scripts, adding install-time behavior that consumers must account for, though this alone is not evidence of poor maintenance.
Only one registry account has publish access. Because the repository is user-owned rather than organization-owned, this indicates limited publishing redundancy, although it does not prove the project is abandoned.
The package and repository are backed by individual user accounts rather than an organization. That leaves less visible institutional continuity, consistent with the single-maintainer concern.
The project is about 4 years old with 15 releases, but only one release in the last 12 months and a median interval of about 68 days indicate a relatively slow cadence.
The repository recorded zero commits and zero active maintainers during the last three months. The recent package release and repository push provide some counterevidence, but current development activity is still weak.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version 1.* || 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.