Healthy and reasonable to depend on. It has a recent stable release, active repository work, tests in the source repository, and clear licensing; the main caveats are a small user base and limited security-process documentation.
82%
Total Score
80
100
94
80
Only one registry account has publish access, which is a continuity concern, although the repository shows a second active contributor.
The repository is owned by an individual user rather than an organization, so the small maintainer and contributor base carries more continuity risk.
The repository has only 3 stars, 1 fork, and no watchers, indicating limited adoption evidence; popularity is supporting evidence rather than a decisive health measure.
No repository security policy is present, leaving vulnerability-reporting and response expectations undocumented.
The only workflow lacks top-level token permissions. No write permission is declared, but explicit least-privilege settings would provide stronger workflow transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
guzzlehttp/psr7 Version ^2.4.5 || ^3.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
webmozart/assert Version ^1.11 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.