A library that implements the Chain of Responsibility pattern.
62%
Total Score
caution
Usable with caveats: maintenance has stopped for more than two years and the package has a license mismatch.
A license file is present, but the manifest declares GPL-2.0 while the artifact license file is detected as MIT. This mismatch creates a meaningful licensing and provenance question for downstream users.
The package has had no release in more than two years and no releases in the last 12 months, which lowers confidence in ongoing maintenance. Its three releases were clustered at launch, suggesting a small or completed project rather than an actively evolving dependency.
There were zero commits and zero active maintainers in the last three months, consistent with maintenance having stopped for more than two years. For a library dependency, this raises abandonment and compatibility risk.
The repository uses Composer, but no security scanning tools were detected. For this small library, the missing scanner is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is less severe for a small, dormant library than an archived or deprecated package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stellarwp/container-contract Version ^1.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.