The package is clearly documented, MIT-licensed, and backed by a small but coherent source repository with tests. Its narrow dependency set and lack of install-time scripts limit operational concerns, but continued maintenance should be verified before adopting it broadly.
58%
Total Score
38
100
75
88
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap. This materially raises the risk that fixes and updates will not arrive promptly.
Only one registry account has publish access, which creates limited publishing redundancy. The repository is user-owned rather than organization-backed, so there is no provided evidence of a broader maintainer base.
The registry namespace and repository owner match, and the repository is owned by the same individual account. This supports package identity, but it does not demonstrate organizational backing or maintainer redundancy.
The package has 68 releases over nearly six years, but none in the last 12 months; the latest release was about 17 months ago. This points to reduced maintenance activity despite a substantial historical release record.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently unhealthy for a small library, but it provides little evidence of an active user or contributor community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0 | — | — |
fig/http-message-util Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.