The focused package has clear documentation, a license, and repository tests, but its narrow scope does not offset the maintenance concern. Pin this release only where its older PHP and dependency constraints remain compatible.
42%
Total Score
50
100
75
83
The package has had no release in about 8 years: its latest release was March 2018, with zero releases in the last 12 months. This is strong evidence of abandonment risk despite the stable 1.0.3 version.
There were zero commits and zero active maintainers in the last 3 months, reinforcing that maintenance has stopped for about 8 years. No newer activity is provided to offset this abandonment risk.
Composer is used for the build, but no security-scanning tooling is present. This is a modest hygiene gap rather than evidence that the package is unfit by itself.
The repository is not archived, which preserves a path for maintenance, but its last push was in March 2018 and is consistent with the inactive release history.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This matters more alongside the package's long maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
ellipse/type-errors Version ^1.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.