The project has a long release history, but no active maintainers or commits were recorded in the last three months. MIT licensing and organization backing help, while the absent security policy leaves a modest transparency gap.
68%
Total Score
75
100
94
83
No commits and no active maintainers were recorded during the last three months. Although the package released twice in the last year, this is a meaningful sign of thin current maintenance.
Composer is used as the build tool, but no security scanning tool was detected. The missing scanning coverage is a modest repository hygiene concern.
The repository has no security policy. That limits transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1 | — | — |
psr/http-factory Version ^1.0.1 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.