The package is clearly licensed, focused, and backed by an organization. Its Composer-only build has no security scanning or security policy, leaving limited assurance beyond the small, transparent artifact.
70%
Total Score
75
100
83
83
Only one release exists, published today, so there is no observed release track record or demonstrated maintenance cadence yet. Its newness explains the gap but does not remove the uncertainty.
There were no commits or active maintainers in the last three months, but the repository was created and pushed today, so this is primarily an absence of historical evidence rather than confirmed abandonment.
Composer is used as the build tool, which fits the package, but no security scanning tools are configured. For a tiny metapackage this is a modest assurance gap rather than a severe risk.
The repository has no security policy. This limits disclosure guidance, although the package is a small type-definition metapackage with no reported workflow or install-time execution risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/psr-event-dispatcher-impl Version ~1.0.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.