The MIT license, included tests, clear README, and organization-backed repository improve transparency and maintainability. The small user base and absent security policy add uncertainty.
65%
Total Score
75
86
75
The package has 11 releases since October 2021, but none in the last 12 months; its latest release was about 17 months ago. This points to slowed maintenance, though the project is not especially young.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. This raises abandonment risk but does not show that the repository is archived.
The repository has 1 star, 2 forks, and 0 watchers, providing little evidence of broad community review or support. Low popularity is supporting caution rather than a verdict on its own.
The linked repository has no security policy, leaving no documented process for reporting and handling vulnerabilities. This is a transparency gap, partially offset by the package's otherwise clear source repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.2 | — | — |
jms/serializer Version ^1.14.0 || ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
rakit/validation Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.