This is a healthy, actively maintained release with strong recent release and commit activity, a stable major version, an unarchived repository, clear MIT licensing, and a modest runtime dependency profile. The repository is organization-owned and includes tests even though tests and a README are not packaged, which compensates for the artifact-level scaffolding gap. The main reservations are that 94% of recent commits come from one contributor, the repository has no security scanning or security policy, and repository popularity is very low; these are meaningful transparency and resilience concerns but do not outweigh the evidence of current maintenance and frequent releases.
82%
Total Score
83
100
94
88
Although four contributors were active, the top contributor made 46 of 49 recent commits, creating substantial contributor-concentration risk. Organization backing partly compensates because maintenance can be handed off within the project.
Composer build tooling is present, but no security scanning tools are configured; this is a moderate supply-chain transparency gap rather than evidence of abandonment.
The repository has no documented security policy, reducing transparency around vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
tempest/reflection Version 3.19.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.