The repository is active, licensed, tested, and backed by an organization. Its single active contributor, absent security policy, and unpinned workflow actions leave maintenance and build-transparency concerns.
62%
Total Score
83
100
81
75
The package includes tests, a changelog, a README, and a GitHub release, which support transparency. However, the README says the library is not ready for general use, has regular breaking changes, and still contains several TODOs.
One contributor made all 33 commits in the last three months, giving the project a very low practical bus factor. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a web-facing library.
Version v0.12.2 is not a prerelease, but the project remains below 1.0 and explicitly warns of breaking changes from version to version. That limits compatibility confidence for dependents.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/container Version ^2.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
substancephp/container Version ^0.6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.