Its small dependency footprint, tests, clear MIT licensing, and organization backing make the package straightforward to evaluate. Pin this version and expect to own compatibility work if its ecosystem changes.
58%
Total Score
83
100
78
88
The package has had no release in more than 5 years, with zero releases in the last 12 months. That long pause is the strongest maintenance concern despite the package's stable 1.0.2 release.
There were no commits or active maintainers in the last 3 months. Combined with the old latest release, this indicates an inactive maintenance line.
Five stars and one fork indicate a small user base. Popularity is only supporting evidence, but the limited adoption provides little external maintenance signal.
Composer is used as the build tool, but no security scanning tooling is present. For this small PHP package that is a hygiene gap rather than a severe risk.
The repository has no security policy. This weakens vulnerability-reporting transparency, though the package's small scope and straightforward source partly limit the concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.