The MIT license, included tests, and matching source repository make the package reasonably transparent to inspect. Its missing security policy and small project footprint leave limited reassurance for long-term support.
38%
Total Score
50
72
83
The latest release was about 9 years ago, with no releases in the last 12 months. This is strong evidence that the package is no longer actively maintained.
There were no commits and no active maintainers in the last 3 months. Combined with the repository's last push being about 8 years ago, this indicates a serious abandonment risk.
There is one open issue and no issue or pull-request activity in the last month. This is consistent with a small, inactive project, though it is less decisive than the release and commit history.
The repository has 11 stars and 1 fork, indicating a small user and contributor footprint. Popularity is supporting evidence, but this modest footprint adds little maintenance reassurance.
Composer is used as the build tool, but no security scanning tool is reported. The missing scanning is a hygiene gap, not a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mouf/picotainer Version ^1.0 | — | — |
jeremeamia/superclosure Version ^2.0 | — | — |
container-interop/container-interop Version ^1.0 | — | — |
container-interop/definition-interop Version ~0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.