The repository is small and has no security policy or automated security scanning. Its lone release is over six years old, and the proprietary licensing makes long-term use and redistribution difficult.
35%
Total Score
50
100
50
75
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. This leaves redistribution and usage rights unclear for an open-source dependency.
This package has only one release, published over six years ago, with no releases in the last 12 months. That strongly suggests abandonment or an unmaintained dependency.
The repository is owned by an individual rather than an organization. That is not inherently unhealthy, but it provides less visible continuity than organization-backed maintenance when activity has already stopped.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide no external evidence of an active user or contributor community.
Composer is used for builds, but no security scanning tool is configured. The missing scanner is a modest transparency and maintenance gap rather than evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.