The artifact includes tests, a matching organization-owned repository, and a clear Apache-2.0 license. No security policy or scanning is present, leaving transparency and ongoing maintenance less established.
64%
Total Score
75
88
83
The package is 0 days old with only 1 release, so there is no demonstrated release track record; its recent publication explains why this evidence is limited rather than severe.
The repository has 0 commits and 0 active maintainers in the last 3 months, leaving no observed maintenance capacity beyond the initial publication.
Composer build tooling is present, but no security-scanning tools were detected; this is a modest hygiene gap for a package with no established history.
The repository has no security policy. This is a transparency gap, although the package is small and the absence is less consequential than it would be for a widely deployed service or application.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version 2.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.