Security scanning and a security policy are absent, and the project has one maintainer with minimal adoption. Tests, release notes, and a matching repository provide useful transparency.
58%
Total Score
50
75
50
The package has four releases, but none in the last four years; the latest release was published in March 2022. This indicates a significant maintenance gap for a library dependency.
One registry maintainer publishes the package. This is a thin publishing base, but it matches the individually owned repository and is not by itself evidence of unsafe maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release pause. This raises abandonment risk, although the repository is not archived.
The repository has one star and no forks, providing little community evidence or external support. Low popularity is supporting evidence rather than a decisive health verdict.
Composer is used for the build, but no security-scanning tools are configured. The missing scanning coverage is a modest transparency and maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
koriym/http-constants Version ^1.2 | — | — |
laminas/laminas-xml2json Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.