Clear documentation, tests, and a permissive license support integration. The workflow limits permissions and uses security scanning, though all five action references are unpinned.
74%
Total Score
50
100
88
75
The repository is owned by an individual user rather than an organization, so the single registry maintainer provides limited visible backing; there is no stronger ownership evidence to compensate.
This is the first release, published today, with only one release and no established cadence. That is expected for a new package but leaves maintenance and abandonment risk unproven.
There were no commits and no active maintainers in the preceding three months, but the repository and release are only hours old, so this is insufficient history rather than evidence of abandonment.
The repository has zero stars, forks, and watchers. For a package released today this is weak supporting evidence, not a standalone health verdict.
No repository security policy was found. This is a modest transparency gap for reporting vulnerabilities, but it is not severe for a newly published small package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.