Documentation and licensing are in place, with a small, understandable runtime dependency set. The project has had no commits or releases since March 2017, and it has no tests or security policy, making future fixes and maintenance uncertain.
38%
Total Score
25
100
72
75
The package has only three releases, with the latest published in March 2017 and none in the last 12 months. This long period without releases is a substantial maintenance concern.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with no activity since March 2017. This materially increases abandonment and compatibility risk.
Registry publishing access is held by one maintainer, and the repository is owned by an individual rather than an organization. Combined with the long inactivity period, this leaves limited visible maintenance capacity.
The repository has 5 stars and 1 fork, providing little evidence of a broad support community. Popularity is only supporting evidence, but it does not offset the inactivity.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest hygiene concern rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.3 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.