The package is well documented, licensed, tested, and backed by a matching organization repository. Its single release is about 5 years and 7 months old, with no recent commits and no security policy, so maintenance risk is significant.
58%
Total Score
63
100
75
83
This is the package's only release, published about 5 years and 7 months ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
There were no commits and no active maintainers in the last 3 months, consistent with a project that has been inactive for years.
There are no open issues or pull requests and no recent activity. This is neutral for a small stable package, but it provides no evidence of current maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance-hygiene gap.
The linked repository is not archived, but its last push was in December 2021, so the non-archived status does not offset the clear inactivity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aura/web Version ^2.1 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.