It has only two releases and no activity since March 2022. The MIT license, direct dependencies, and matching repository make its contents understandable, but do not offset its abandonment.
15%
Total Score
50
100
50
83
Packagist marks the entire package as abandoned, with no replacement package provided. This is a direct warning against taking a new dependency on it.
The package has only two releases, with the latest released in March 2022 and none in the last 12 months. This strongly supports an abandonment concern.
There were zero commits and zero active maintainers in the last three months, consistent with the archived repository and lack of recent releases.
The linked repository is archived and was last pushed in March 2022, indicating that active maintenance has ended.
There has been no recent issue or pull-request activity. While a quiet issue tracker can be normal for a small contract package, it provides no evidence of ongoing maintenance here.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0.1 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.