A stable 1.2.0 release, clear README, repository tests, release notes, and an MIT license support adoption. The long publishing and development pause means future fixes may be uncertain.
58%
Total Score
75
88
100
The package has 17 releases and a short median interval of about 5 days, but none in the last 12 months; the latest release was about 18 months ago. This substantial pause lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the last 3 months, consistent with the repository's last push about 18 months ago. This is the strongest evidence that maintenance has paused.
Composer build tooling is present, but no security-scanning tools were detected. That is a transparency gap, though it is less serious because the repository has a SECURITY.md policy and ordinary build configuration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/uid Version ^6.4 || ^7.0 | — | — |
guzzlehttp/psr7 Version ^2.7 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.