The package includes tests, release notes, and regular registry releases, but its tiny repository has no recent commit activity and offers no security policy. The linked repository also does not identify this package in its name or README, which weakens provenance confidence.
55%
Total Score
75
50
71
50
Ten runtime dependencies create a meaningful transitive maintenance surface for a small package. The profile is not inherently unsafe, but it increases the cost of tracking compatibility and updates.
The release declares a proprietary license, so it is licensed even though no license file was detected. This is not a missing-license gap, but the terms may restrict adoption in open-source projects.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the recent release shows publishing activity, the lack of observed development activity lowers maintenance confidence.
The repository name does not match the package name and its README does not mention the package. A monorepo relationship may explain this, but the collected evidence does not establish that the repository is specifically for this package.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest supply-chain hygiene gap rather than evidence that the package is unmaintained.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8.2 | — | — |
atto/framework Version ^0.1.4 | — | — |
atto/psr7-module Version ^0.1.0 | — | — |
crell/api-problem Version ^3.8.0 | — | — |
membrane/membrane Version ^0.10.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.