The package is licensed, tested, documented, and has a small runtime dependency surface. Its single maintainer and no commits or releases for over a year leave a meaningful continuity concern; pin v1.2.0 if adopting it.
62%
Total Score
50
100
86
75
Only one registry publishing maintainer is listed, leaving limited visible continuity if that person becomes unavailable. The repository is user-owned, so there is no organization backing shown to offset this thin base.
The registry namespace and repository owner match, but the owner is an individual rather than an organization, so there is limited visible institutional backing.
The package has four releases, but none in the last 12 months and the latest was over a year ago. The initially frequent releases do not compensate for the prolonged current gap.
There were no commits and no active maintainers in the last three months, consistent with the release gap and indicating weak current maintenance.
The repository uses Make and Composer, but no security-scanning tools were detected. This is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 || ^1.1 | — | — |
psr/http-message Version ^1.0 || ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.