The project has a clear README, release notes, repository tests, and a matching MIT license. GitHub Actions use two unpinned references, and the repository has no security policy, leaving moderate maintenance and build-transparency gaps.
68%
Total Score
50
100
88
75
The package is backed by an individual repository owner rather than an organization, so the single registry maintainer represents a relatively narrow ownership base. The repository's tests and release notes provide some compensation.
The package has 19 releases over more than eight years, but none in the last 12 months and its latest release was about 13 months ago. This points to slowing maintenance, though the release history is established rather than abandoned.
The repository had zero commits and zero active maintainers in the last three months. Together with the lack of releases in the last year, this is evidence of currently inactive maintenance.
The project uses Composer and Make, but no security-scanning tools were detected. This is a moderate transparency gap, not evidence that the package is unsafe.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.