Documentation, licensing, and release notes are in place, and the package has no install-time scripts. Its v0.0.3 status, no commits in three months, and five unpinned workflow actions indicate limited maturity and build hygiene.
61%
Total Score
75
79
83
The package is about 5 months old with only two releases, both published on the same day, so its release and maintenance history is still thin. The recent release notes provide some evidence of ongoing publication but not long-term stability.
The repository recorded zero commits and zero active maintainers in the last three months. For a package only about 5 months old, this is a meaningful sign of slowing maintenance, though it is not proof of abandonment by itself.
Composer build tooling is present, but no security-scanning tool was detected. The missing scan is a hygiene gap, while the build setup provides some project structure.
Version 0.0.3 is below a stable major version, which signals an API that may still change and limited maturity for dependency use.
Both workflows were analyzed successfully with no reported audit findings or untrusted checkouts. However, all five action references are unpinned, leaving build inputs less reproducible and increasing workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1 | — | — |
psr/http-message Version ^1|^2 | — | — |
php-http/discovery Version ^1 | — | — |
psr/http-client-implementation Version ^1 | — | — |
psr/http-factory-implementation Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.