The project is very new, with only two releases and no commits or active maintainers in the last three months. A complete README, extensive tests, release notes, organization backing, and a security policy provide useful counterweight.
68%
Total Score
83
100
81
100
The package is only 101 days old and has had two releases, with the latest roughly three months ago; this is limited evidence of long-term maintenance.
There were zero commits and zero active maintainers in the last three months, weakening evidence of ongoing maintenance for a newly released package.
The repository has one star and no forks or watchers, so there is little external adoption evidence; popularity is supporting evidence rather than a verdict.
Composer build tooling is present, but no security-scanning tool was detected; the missing scanner is a modest transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
league/uri-components Version ^7.0 | — | — |
bakame/http-structured-fields Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.