Usable with caveats: the package is actively released, stable, correctly backed by a matching organization repository, and not deprecated. Its very small codebase has no tests or changelog, maintenance is currently concentrated in one contributor, and the repository has no security policy or scanning.
72%
Total Score
67
100
88
90
A README documents the package boundary and registered services, but there are no tests or changelog in either the artifact or repository. For this small integration package the missing tests and release notes are genuine transparency gaps, though the focused README provides some compensating documentation.
One contributor made all four commits in the last three months, creating a real concentration risk. The organization-owned repository provides some handoff capacity, so this is a caution rather than a severe abandonment signal.
The repository recorded four commits in the last three months, showing recent activity, but all activity came from one maintainer.
Composer is used for builds, but no security-scanning tool is configured. The missing scanning is a modest process gap for a small package, not evidence that the release is unsafe by itself.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This lowers transparency, although the package is a small integration component.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
slim/psr7 Version ^1.7 | — | — |
psr/http-message Version ^2.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.