The package includes a README and tests, and it has no install-time scripts or deprecation notice. Its small release history and roughly 16 months without commits make future fixes uncertain.
58%
Total Score
50
79
75
Only two releases exist, with none in the last 12 months and about 16 months since the latest release. This indicates limited release momentum and raises maintenance uncertainty.
The repository recorded no commits and no active maintainers during the last three months, consistent with about 16 months without observed updates. This materially increases the risk that defects or compatibility issues will remain unresolved.
The repository has zero stars, forks, and watchers, offering no supporting evidence of a broad maintainer or user community. Popularity is only supporting evidence, so this contributes a limited caution.
Composer is used for the build, but no security scanning tools were detected. That is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
relay/relay Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
laminas/laminas-diactoros Version ^3.5 | — | — |
laminas/laminas-httphandlerrunner Version ^1.5.0 | ^2.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.