The package is clearly licensed, documented, and tested, with no install-time scripts. Source activity has stopped for three months, and the repository has no security policy or automated security scanning.
68%
Total Score
50
50
94
75
Fourteen runtime dependencies make the package depend on a moderately broad supporting stack, which adds update and compatibility surface, but the profile is coherent for a base application framework.
The repository recorded zero commits and zero active maintainers in the last three months. Although releases have occurred recently, the lack of recent source activity is a maintenance concern.
Composer is used for builds, but no security scanning tool was detected. This is a transparency and maintenance-process gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency but does not by itself make the release unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
psr/container Version ^2.0 | — | — |
tobento/service-dir Version ^2.0 | — | — |
tobento/service-clock Version ^2.0 | — | — |
tobento/service-dater Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.