Usable with caveats: it is a clearly identified, MIT-licensed package with documentation, tests in the repository, and a recent stable release. However, it has only two releases over about eight months and no recorded commits in the last three months, so its long-term maintenance is not yet established.
68%
Total Score
67
100
83
90
Only one registry publishing account is listed, which limits visible publishing redundancy; this concern is partly offset by the repository being organization-owned.
Only two releases have been published over about eight months, with roughly 252 days between them. This is limited history for establishing dependable long-term maintenance, although the latest release is recent.
The repository recorded zero commits and zero active maintainers in the last three months. A recent push and one merged pull request show some activity, but the observed maintenance cadence remains thin.
The repository has one star, no forks, and no watchers, indicating little community adoption or independent visibility. Popularity is supporting evidence rather than a requirement, but it offers little additional confidence here.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.