Documentation, tests, licensing, and release notes are strong, with a current stable release and recent repository activity. Maintenance remains concentrated in one contributor, and all four workflow actions are unpinned.
72%
Total Score
63
100
88
88
Only one registry account has publish access. The linked repository is also owned by a single user, so there is no organization backing shown to compensate for this concentration.
The package has existed for more than 11 years and released once in the last 12 months, but only six releases overall make its long-term cadence relatively sparse.
One contributor made all two recent commits, giving the project a complete short-term contributor concentration and increasing continuity risk.
The repository has only two commits from one active maintainer in the last three months. Recent activity exists, but the observed maintenance volume is thin.
Composer build tooling is present and the repository includes static-analysis and test configuration, but no security scanning tool was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
guzzlehttp/psr7 Version ^2.8 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.