A clear README, repository tests, and a documented release note make integration straightforward. The organization-backed repository remains available, but release activity has stopped and workflow dependencies are unpinned.
67%
Total Score
75
100
88
50
The latest registry release was in September 2023, with no releases in the following three years. This is a meaningful maintenance concern, though the repository was pushed more recently.
There were no commits and no active maintainers during the last three months. The more recent repository push partly offsets this, but does not restore a currently active development cadence.
The repository uses Composer build tooling, but no security scanning tools were detected. That is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a minor transparency gap for a dependency, not a standalone adoption blocker.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both action references are unpinned. The absence of a top-level permissions block is not a concern by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.