Its workflow uses three unpinned actions and the repository has no security policy. Repository documentation, tests, and licensing are solid, but the project provides limited evidence of current support.
48%
Total Score
50
78
75
The package has 35 releases since 2015, but none in the last three years; the long release gap is a substantial abandonment and compatibility concern.
The repository is owned by an individual user rather than an organization, so the package has limited visible institutional backing to offset its inactive maintenance.
There were no new or merged pull requests and no issue activity in the last month, consistent with the broader evidence of limited recent maintenance.
The linked repository reports zero stars, forks, and watchers. Popularity is only supporting evidence, but this gives little external evidence of adoption or community support.
The project uses Composer and Make, showing basic build structure, but no security-scanning tools were detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.0|^2.0 | — | — |
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
guzzlehttp/promises Version ^1.1|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.