Usable with caveats: this is a small, clearly identified MIT package with a simple dependency profile and a documented release. However, it has had no release or commit activity for over three years, so maintenance appears dormant.
62%
Total Score
50
100
83
75
The package has only two releases and none in the last 12 months; its latest release was over three years ago. That is a meaningful maintenance concern, although the package is small and narrowly scoped.
There were no commits and no active maintainers in the last three months, following more than three years without a release. This indicates dormant maintenance and increases the risk that compatibility issues will remain unresolved.
The repository has two open issues and no issue or pull-request activity in the last month. The small issue count is not severe, but the absence of recent activity reinforces the maintenance concern.
The repository has only two stars, one fork, and no watchers. This is weak supporting evidence for project maturity, though low popularity alone is not a reason to reject a small foundational interface.
Composer is used as a build tool, but no security scanning tool is configured. For this tiny package the missing scanner is a hygiene gap rather than a severe supply-chain risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.