Usable with caveats: it is actively released, correctly backed by a matching organization repository, and the latest version is stable. The small single-contributor base and lack of tests or a security policy leave meaningful maintenance and transparency gaps.
68%
Total Score
75
100
88
90
The package includes a README, but neither the artifact nor repository has tests or a changelog. The README explains this narrow factory-integration package, yet the absence of tests still leaves behavior less verifiable.
One contributor made all 4 commits in the last 3 months, creating a concentrated maintenance risk. Organization backing provides some handoff potential, but no second active contributor is shown.
The repository recorded 4 commits in the last 3 months, showing ongoing activity. All activity came from one maintainer, which limits evidence of durable maintenance capacity.
Composer is used as the build tool, but no security scanning tools are configured. The build setup is appropriate, while the missing scanning adds a modest transparency gap.
The repository has no security policy. For a small adapter this is not a severe risk, but it leaves vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^2.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
laminas/laminas-diactoros Version ^3.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.