The repository is backed by an organization, uses Composer, and has no install-time scripts. The package has no README or security policy, leaving integration and maintenance practices poorly documented.
58%
Total Score
75
50
75
75
Six runtime dependencies create a meaningful dependency surface for this small package, including framework and HTTP components, but no unusually extreme dependency count is shown.
The manifest declares a proprietary license, so the release is licensed, but no license file was detected to clarify its terms for consumers.
This is the only release in roughly 10 months, so there is little evidence of an established release cadence or sustained maintenance.
There were no commits and no active maintainers in the last three months, providing weak evidence of ongoing maintenance after the initial release.
The repository uses Composer, but no security scanning tooling was detected, leaving automated dependency or code checks unobserved.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1 | — | — |
atto/framework Version ^0.1.0 | — | — |
nyholm/psr7-server Version ^1 | — | — |
laminas/laminas-stdlib Version ^3.16 | — | — |
laminas/laminas-httphandlerrunner Version ^2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.