The package includes tests, a README, and an MIT license, with no install-time scripts. Its only release was 720 days ago, recent commit activity is absent, and the linked repository does not identify the package in its README. Pin this version only if its limited maintenance and repository identity are acceptable.
57%
Total Score
75
71
75
This is the package's only release, published 720 days ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance, although the repository was pushed more recently.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push provides some counterevidence, but current development activity remains thin.
The repository name does not match the package name and its README does not mention this package. Although the organization backing is consistent, the collected evidence does not clearly tie the repository to this release.
Composer is used for the build, but no security scanning tools were detected. This is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This lowers transparency for a package intended to be integrated into applications.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.6 | — | — |
psr/http-client Version ^1.0 | — | — |
webmozart/assert Version ^1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.