The Apache-2.0 license, matching repository, and organization backing provide good transparency. Its minimal metapackage design limits complexity, but there is not yet enough history to establish dependable maintenance.
68%
Total Score
75
100
88
83
The package is 0 days old with only 1 release, so its maintenance and release reliability are not yet demonstrated.
There were 0 commits and 0 active maintainers in the past 3 months; because the repository was created at release time, this is mainly an absence of demonstrated history rather than evidence of abandonment.
The repository uses Composer tooling, but no security scanning tools were detected; for this very small metapackage, the missing scanning is a minor hygiene gap.
No security policy is present, which is a transparency gap, though the package is a minimal type-definition metapackage with no install scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/php-di-invoker-impl Version ~2.3.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.