It has a clear MIT license, a usable README, and a documented bug-fix release. The project has no recent activity or security policy, so choose the listed replacement instead.
12%
Total Score
50
83
Packagist marks the entire package as abandoned and names ellipse/session as its replacement, making continued adoption a serious maintenance risk.
The package has had no releases in more than eight years despite 36 historical releases, indicating long-term abandonment rather than an active maintenance cycle.
The linked repository is archived and was last pushed in March 2018, so new fixes and maintenance should not be expected.
The repository has no security policy, which is a transparency gap for a session-management library and is not offset by the project's archived state.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hansott/psr7-cookies Version ^1.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.