The small dependency footprint, BSD-3-Clause license, tests, and changelog provide useful foundations. However, the package has had no registry releases for about 8 years, no recent repository activity, and the linked repository does not clearly identify this package.
42%
Total Score
75
100
67
75
The package is about 8 years old, but has had no releases in the last 12 months; the long release silence is a substantial maintenance concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, supporting concern that active maintenance has stalled.
The repository name does not match the package name and its README does not mention the package, so the source-to-package relationship is not clearly established.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The release is marked stable rather than prerelease, but the reported latest version is 2.7.11 while the assessed release is 3.3.2, creating a notable version-history inconsistency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 | — | — |
zendframework/zend-stdlib Version ^3.1 | — | — |
container-interop/container-interop Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.