Standalone session implementation that does not rely on the PHP session module or the $_SESSION global, ideal for ReactPHP applications
61%
Total Score
caution
Usable with caveats: no release or commit activity since January 2025 raises maintenance risk.
The package has 21 releases since August 2021, but none in the last 12 months; its latest release was January 13, 2025. The long inactivity period lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful sign of currently inactive development, although the repository is not archived.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a session-handling library.
All 3 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image. There are no untrusted checkouts or script-injection findings, which limits the concern to workflow reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1 || ^2 | — | — |
psr/simple-cache Version ^1 || ^2 || ^3 | — | — |
dflydev/fig-cookies Version ^3.0 | — | — |
psr/http-server-handler Version ^1 | — | — |
psr/http-server-middleware Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.