The README is useful, dependencies are lightweight, and the repository is organization-backed with security scanning. However, no releases or commits appear after late 2023, and the license mismatch and unpinned workflow actions reduce confidence in ongoing maintenance and publishing hygiene.
58%
Total Score
75
100
83
75
The artifact declares MIT and includes a license file, but the detected license text is BSD-3-Clause, so the release has licensing evidence but an unresolved mismatch.
The package has only 3 releases, all concentrated between October 31 and November 8, 2023, with none in the last 12 months; this indicates stalled maintenance for a package over 2 years old.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the old release history and raising abandonment concerns.
Both workflows were analyzed without dangerous triggers or audit findings, but all 18 action references are unpinned, leaving routine build dependencies exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.