Clear MIT licensing, thorough documentation, tests, and a matching organization repository improve transparency. Its single release and no commits or contributors recorded over three months leave maintenance capacity unproven.
68%
Total Score
75
79
50
This is the package's first and only release, published today, so there is no release history or cadence demonstrating sustained maintenance yet.
No commits and no active maintainers were recorded during the last three months. Because the package was released today, this may reflect its newness, but it still provides no evidence of an established maintenance track record.
The repository uses Composer build tooling, but no security scanning tools were detected. This is a modest supply-chain hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting expectations undocumented. This lowers transparency but is not severe enough to make the release unfit on its own.
Version v0.1.0 is an early non-stable major release, which indicates the API may still change substantially even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.