Usable with caveats: the release is licensed, documented, tested, and backed by a matching repository, but it has only one release and no commits in the last three months. Zero adoption signals and incomplete repository security hygiene add uncertainty for a new dependency.
60%
Total Score
50
100
78
80
There have been zero commits and zero active maintainers in the last three months, a meaningful warning that maintenance may have stopped after the initial release.
A single registry maintainer is consistent with the matching user-owned repository, but it leaves little visible publishing redundancy if that maintainer becomes unavailable.
This is a young package with one release over 187 days and no established release cadence, so its long-term maintenance is unproven.
There are no open issues or pull requests and no recent issue or merge activity; this is neutral for a small new project but offers no evidence of active community maintenance.
The repository has zero stars, forks, and watchers. Popularity is not decisive, but this provides no supporting evidence of community use or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8.2 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.1 | — | — |
symfony/http-client Version ^7.4|^8.0 | — | — |
symfony/framework-bundle Version ^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.