The release is documented, licensed, tested, and clearly linked to its own repository. Workflow references are unpinned and no security policy is present, offering little additional maintenance assurance.
18%
Total Score
0
64
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption concern even though the assessed release is otherwise stable.
The repository recorded zero commits and zero active maintainers in the past 3 months. Together with the archived and abandoned status, this supports a strong abandonment concern.
The linked repository is archived, indicating that normal project maintenance has ended. Its last push was about 11 months ago, which does not compensate for the archived state.
The package has existed since July 2020 with 10 releases and a latest release in October 2025, but only one release occurred in the last 12 months. This history provides some maturity but not current maintenance confidence.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is secondary to the package's abandoned and archived status.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0.1 | — | — |
psr/http-message Version ^2.0 | — | — |
bermudaphp/config Version ^2.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.