The stable v4.3.0 release has a small dependency surface, a clear README, and a matching source repository. Organization backing and release notes add useful transparency, but compatibility should be confirmed before adoption because the project is mature but inactive.
58%
Total Score
75
100
75
50
The package has 11 releases since June 2015, but none in the last 12 months and the latest release was in August 2019. This is strong evidence of prolonged inactivity, although the long history suggests the project is established.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's last release being in August 2019. This materially increases maintenance and abandonment risk.
Composer is used for the build, but no security-scanning tools were detected. The absence of scanning reduces maintenance assurance, though it is not evidence that the release is unsafe.
The repository has no security policy, leaving no documented path for reporting vulnerabilities. This is a transparency gap, particularly for middleware handling authentication-related request data.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version >=6.0 | — | — |
paragonie/random_compat Version >=2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.