The MIT license, tests, matching source repository, and one runtime dependency make the package straightforward to evaluate. Its small public footprint leaves limited evidence of long-term support.
62%
Total Score
75
100
83
88
The package has 12 releases over roughly three years, but only one release in the last 12 months and the latest release is about six months old. This indicates a sparse current cadence.
There were no commits and no active maintainers during the last three months. Combined with the sparse recent release history, this weakens evidence of ongoing maintenance.
The repository has zero stars and zero forks, with one watcher. This is limited supporting evidence of community adoption, but popularity alone is not decisive.
Composer build tooling is present, but no security scanning tool was detected. That is a maintenance and transparency gap, though not a severe risk by itself.
The repository has no security policy. For a library handling HTTP messages, this reduces clarity about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.