The repository has no security policy or automated security scanning, and its zero-star footprint offers little independent evidence. Tests, documentation, and organization backing provide some reassurance, but the project is still early.
62%
Total Score
75
100
81
83
This is the package's only release, published about 99 days ago, so there is not yet enough history to demonstrate sustained maintenance.
No commits or active maintainers were observed in the past three months; combined with the single-release history, this leaves ongoing maintenance unproven.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, though the package is still young and popularity alone is not decisive.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-maintenance gap for a package handling session data.
The repository has no published security policy, reducing transparency about how vulnerabilities in this security-sensitive library should be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 || ^2.0 | — | — |
componenta/default-value Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.