Usable with caveats: the release is well packaged, licensed, tested, and backed by a matching repository, but maintenance appears dormant. The last release and repository push were over four years ago, with no recent commits and no security policy.
58%
Total Score
50
75
75
Only one registry account has publishing access. This is compatible with an individual-owned project, but it leaves limited apparent publishing redundancy when combined with the absence of recent repository activity.
The registry namespace and repository owner match, providing consistent ownership evidence. The owner is an individual rather than an organization, so the single-maintainer concern is not offset by organizational backing.
The package has only 3 releases and none in the last 12 months; its latest release was published over four years ago. This is a meaningful maintenance concern, though the package has a real release history rather than being an unproven one-off.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since the last release. The repository is still present and unarchived, but there is no evidence of current development.
The project uses Make and Composer build tooling, but no security scanning tools were detected. The build tooling supports maintainability, while the missing scanning reduces supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^0.8.1 | — | — |
friendsofphp/php-cs-fixer Version ^3.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.