The release is still a pre-release, and all three workflow action references are unpinned. It is backed by an organization, has repository tests, release notes, license coverage, and security scanning.
62%
Total Score
75
86
50
A post-update-cmd script runs during dependency updates. This is worth checking for update-time behavior, but the signal does not show a destructive or unusual script.
The package is 783 days old with five releases and only one release in the last 12 months, indicating a slow release cadence despite a recent release being available.
The repository recorded zero commits and zero active maintainers during the last three months, a meaningful sign of currently limited maintenance activity.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; Psalm and other project controls provide only partial compensation.
The assessed version is a pre-release, and all recent releases are pre-releases, so the public API may still change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version ^1.57 | — | — |
spiral/core Version ^3.14 | — | — |
spiral/hmvc Version ^3.14 | — | — |
psr/container Version ^2.0 | — | — |
google/protobuf Version ^4 || ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.