The package is clearly packaged, licensed, documented, and tested, with a repository that matches its name. Its release and commit activity stopped over four years ago, and no security policy or scanning is present.
61%
Total Score
0
88
50
There were no commits and no active maintainers in the last 3 months. Combined with the old latest release, this is strong evidence that maintenance has stalled.
The package has only 3 releases over roughly 9 years, with no releases in the last 12 months and a median interval of about 821 days. This indicates very slow maintenance and raises abandonment risk.
The repository uses Composer and Make, showing basic build tooling, but it has no security scanning tools. That is a transparency and maintenance gap, though not severe by itself.
The repository has no security policy, leaving no published process for reporting vulnerabilities or communicating fixes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ~2.1.0 | — | — |
psr/http-client Version ~1.0 | — | — |
psr/http-message Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.