The MIT license, README, tests, and release notes provide basic transparency, with no install-time scripts. Its maintenance record is effectively stopped, and the registry marks this package abandoned in favor of psr7-session; choose the replacement instead.
12%
Total Score
0
50
100
Packagist marks the entire package abandoned and names psr7-session as its replacement. Package-level abandonment is a severe adoption risk, despite the package being licensed and documented.
The latest release was in November 2015, with no releases in the last 12 months and only four releases overall. This long release gap strongly indicates abandonment.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the package's decade-long lack of releases.
The linked repository name does not match the package name and its README does not mention the package, so the repository may be for a replacement or different project rather than this release.
The repository is not archived, but it was last pushed on November 16, 2015. Its unarchived status does not compensate for the absence of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.