The package includes tests, a clear README, release notes, and a repository that matches the package. There is no security policy, while organization backing partly offsets the single registry maintainer.
68%
Total Score
75
100
79
75
The package is about 13 months old with three releases and only one release in the last 12 months, indicating a slow release cadence for a still-young package.
The repository recorded no commits and no active maintainers during the last three months, which is a meaningful sign of currently quiet maintenance despite the recent release.
The project uses Composer and Make, but no security-scanning tooling was detected; this is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no SECURITY.md or other security policy, leaving vulnerability reporting and response expectations unclear.
Version 0.3.0 is not a stable-major release, so API changes remain possible, although it is not marked as a prerelease and recent versions have been consistently stable releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
technically/null-container Version ^2.0 | — | — |
technically/array-container Version ^2.0 | — | — |
technically/dependency-resolver Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.