The package has a small dependency surface and includes automated tests, which supports straightforward maintenance. Consumer documentation is absent, workflow actions are unpinned, and there is no security policy or scanning setup.
58%
Total Score
75
100
75
67
The package includes tests and the repository uses GitHub Releases, both of which support basic project maturity. The absent README is a documentation gap for a library consumers must integrate with, while the absent changelog is normal packaging practice.
The package has had no releases in the last 12 months, and its latest release was about three years ago. This is a meaningful maintenance concern despite the stable 1.0.1 version.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive since September 2023. This materially raises abandonment risk.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption signal to offset the limited activity.
Composer build tooling is present, but no security scanning tools are configured. This is a modest transparency and maintenance gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.