Repository tests, security scanning, and release notes provide useful transparency for this small library. The license mismatch and unpinned workflow actions require attention, while the project is too new to demonstrate durable maintenance.
68%
Total Score
50
88
67
The artifact includes a license file, but the manifest declares MIT while the detected license is LGPL-2.1. The release is licensed, yet the mismatch creates avoidable legal uncertainty.
The package and repository are owned by the same individual account, which is consistent ownership but provides no organizational backing or redundancy.
The package is only 3 days old with 3 releases and a median interval of about 2 days, showing active initial work but no established maintenance record yet.
The repository records zero commits and zero active maintainers over the last 3 months. Because the package is only 3 days old and has recent releases, this limits confidence more than it proves abandonment.
No repository security policy was found. This is a modest transparency gap for reporting vulnerabilities, though it is not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/http-client Version ^1.0.3 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
php-http/discovery Version ^1.20.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.