Usable with caveats: the release is licensed, tested, documented, and backed by an active organization, but the project is young and shows no commits or active maintainers in the last three months. Limited popularity and missing security policy add maintenance and transparency concerns.
67%
Total Score
75
100
83
88
The package is only 321 days old with three releases and a median interval of about 161 days, showing a real release history but limited maturity and a relatively slow cadence.
There were zero commits and zero active maintainers in the last three months, a meaningful maintenance warning; the recent push and release provide some compensating evidence but do not establish sustained activity.
The repository has zero stars, one fork, and zero watchers, indicating a very small user and contributor footprint. Popularity is supporting evidence only, but this increases uncertainty for a young package.
Composer build tooling is present, but no security-scanning tool was detected, leaving a transparency and maintenance-control gap for a package intended to run in WordPress projects.
The repository has no security policy, so users lack a documented channel and process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.