This release appears healthy and suitable to depend on: it is actively maintained, with 21 releases in 52 days, 120 commits from three active contributors in the last three months, recent repository activity, tests, a substantial README, a clear GPL-3.0-or-later license, and no deprecation or archive status. The package is still young and uses a non-stable 0.x version, so API evolution is a consideration; repository security-process coverage is also incomplete because no security policy or security scanning tooling was observed, and workflow token permissions are not explicitly constrained. These are manageable transparency and process gaps rather than evidence of abandonment.
85%
Total Score
90
100
83
80
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.4 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.