The organization-owned repository includes tests, a matching package name, and an Apache-2.0 license. It has no install-time scripts, but its longer-term maintenance and security practices are not yet established.
64%
Total Score
75
100
88
88
This is the package's first recorded release, published 0 days ago with only one release, so there is no history showing sustained maintenance or release reliability.
There were 0 commits and 0 active maintainers in the previous 3 months. Because the repository and release are only 0 days old, this is mainly missing maintenance evidence rather than proof of abandonment.
Composer is used as the build tool, but no security scanning tool was detected. For a new package, that leaves a meaningful security-process gap.
The repository has no security policy, which limits guidance for reporting vulnerabilities and is a modest transparency gap for a dependency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
php-di/invoker Version 2.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.