It has a focused dependency set, a valid MIT license, repository tests, and organization ownership. The long pause since its last release and commit activity makes future fixes uncertain; pin this version if adopting it.
61%
Total Score
75
100
83
83
The package has a mature history with 382 releases since 2019, but it has had no release in the last 12 months and its latest release was in February 2025, indicating a meaningful maintenance pause.
There were zero commits and zero active maintainers in the last three months, consistent with the release pause and raising the risk that defects will not receive prompt fixes.
The repository has no stars or forks and only one watcher. This is weak supporting evidence, though low popularity alone is not a health verdict for a focused library.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance-hygiene gap.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.1 | — | — |
symfony/psr-http-message-bridge Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.