Usable with caveats: the package is licensed, tested, clearly backed by its matching organization repository, and has release notes, but maintenance appears slow with no releases in the last 12 months and no commits in the last 3 months. Its small user base and limited security tooling add uncertainty.
62%
Total Score
83
100
78
75
Only two releases have been published over about 2 years and 4 months, with no release in the last 12 months. That is a meaningful sign of slow maintenance for a dependency.
The repository recorded zero commits and zero active maintainers during the last 3 months. Combined with no release in the last 12 months, this indicates limited current maintenance.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but this provides little external evidence of adoption or community support.
Composer build tooling is present, but no security scanning tools were detected. That leaves a security-process gap, though it is not evidence that the package is malicious.
The repository has no published security policy. This weakens vulnerability-reporting transparency, although it is a smaller concern for a small package with no other workflow red flags.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.