Usable with caveats: the package is well-documented, tested, licensed, and its repository matches the package, but it is very young and has had no commits or active maintainers in the last three months. Zero adoption signals and no security policy add uncertainty for a security-sensitive library.
62%
Total Score
50
100
78
90
One registry publishing account provides a thin maintainer base, which limits redundancy; the individual repository ownership is consistent with that account but does not compensate for the narrow bus factor.
The registry namespace and repository owner correspond, but the project is backed by an individual rather than an organization, leaving limited institutional continuity.
The package is only about 11 months old and has just two releases, so its maintenance record is still limited despite the short three-day interval between those releases.
The repository recorded zero commits and zero active maintainers in the last three months. For a young package this is a meaningful maintenance concern, even though the latest push was near the latest release.
There are no open issues or pull requests and no activity in the last month; while this avoids an unresolved backlog, it also provides little evidence of an engaged user or maintainer community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version 1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.