Risky to adopt for a new project: the package has had no registry release for nearly nine years and no recent repository activity. It is licensed and not deprecated or archived, but its 13-character README and lack of package references in the repository provide little maintenance or usage transparency.
42%
Total Score
50
71
75
The latest release was published nearly nine years ago, with only two releases overall and none in the last 12 months. This strongly suggests the package is no longer actively maintained.
The repository recorded no commits or active maintainers in the last three months, consistent with the very old latest release and indicating a substantial abandonment risk.
The package includes a README, but it is only 13 characters long and provides essentially no integration guidance. Missing tests and a changelog are normal for a published artifact, while the repository also has no tests or changelog to offset the documentation gap.
The repository name matches the package, which supports the link, but the README does not mention the package. That leaves consumers with little evidence about how this library is intended to be used.
The repository has no security policy. This is a transparency gap, although the package is small and the available signals do not show a specific security incident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
atomwares/atom-http Version ^1.0 | — | — |
atomwares/atom-interfaces Version ^1.0 | — | — |
http-interop/http-middleware Version ^0.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.