The project has organizational backing, a complete README, tests in its repository, and recent commits. However, releases are infrequent and all recent commits come from one contributor, while the naming signal indicates a serious identity concern.
42%
Total Score
75
100
78
88
The signal says the package borrows the identity of wikimedia/less.php, which has far more downloads and stable releases; despite zero artifact overlap, this is a severe risk that consumers may have intended the lookalike package.
The package has only five releases since July 2019, with no releases in the last 12 months and a median interval of about 18 months. This indicates a slow maintenance cadence, although the repository shows recent activity.
One contributor made 100% of the three recent commits. Organizational ownership provides some handoff capacity, but the observed activity still shows concentrated maintenance risk.
Three commits were made in the last three months, showing ongoing activity, but only one maintainer contributed them. The activity is positive but narrow.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1 || ^2.0 | — | — |
wikimedia/scoped-callback Version ^3.0 || ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.