The package is clearly licensed, documented, and backed by an organization with repository tests. Its small audience and missing security policy leave less independent assurance for a substantial runtime dependency.
65%
Total Score
83
50
89
75
Nineteen runtime dependencies make this a relatively broad dependency graph for a runtime library, increasing transitive maintenance exposure, though the listed dependencies are coherent with its functionality.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, a meaningful sign that maintenance may have slowed after the release period.
The repository has 4 stars, 0 forks, and 0 watchers. This indicates limited adoption and review, but popularity is supporting evidence rather than a health verdict.
Composer build tooling is present, but no security scanning tools were detected. That reduces automated assurance for a package with a substantial runtime dependency graph.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
boson-php/uri Version ^0.19 | — | — |
psr/container Version ^2.0 | — | — |
react/promise Version ^3.0 | — | — |
boson-php/http Version ^0.19 | — | — |
boson-php/saucer Version ^0.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.