The library includes tests, release notes, and a clear MIT license. Its small release history and no recent commit activity leave maintenance uncertain; pin v1.1.0 if adopting it.
60%
Total Score
67
100
88
75
The package has only two releases, both published about 702 days ago, with no releases in the past 12 months. This is a meaningful maintenance concern despite the linked repository being available.
There were zero commits and zero active maintainers in the latest three months. This weakens confidence in ongoing maintenance, even though the repository metadata records a later push date.
The repository has one open issue and seven open pull requests, with no issues closed or pull requests merged in the past month. The unresolved queue suggests limited current maintenance.
The project uses Make and Composer, but no security-scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, though it is not by itself evidence of an active defect.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
beberlei/assert Version ^3.0 | — | — |
guzzlehttp/psr7 Version ^1.7 | ^2.0 | — | — |
psr/http-message Version ^1.0 | — | — |
justinrainbow/json-schema Version ^5.3 | ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.