The package is small and clearly linked to its repository, with an MIT license and a stable release. Its maintenance, testing, and security evidence are too weak for a dependable library dependency.
42%
Total Score
50
75
50
Only one release exists, published nearly nine years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a library dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving no current maintenance evidence.
The package declares eight install- and update-time Composer lifecycle scripts, increasing installation complexity and the amount of code executed during dependency operations.
The release has a README and GitHub release notes, but the README is only 17 characters and neither the package nor repository contains tests. The release notes provide limited documentation but do not offset the maintenance concern.
The repository has zero stars, forks, and watchers, providing no supporting evidence of adoption or community oversight. Popularity is only supporting evidence, so this reinforces rather than determines the risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
siriussupreme/sirius-container Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.