The repository includes tests, a changelog, security guidance, and static analysis, while the package is clearly licensed and not deprecated. Its small organization-backed project has had no commits or releases for about 21 months, so future maintenance is uncertain.
62%
Total Score
50
50
94
83
There were zero commits and zero active maintainers in the last three months, consistent with roughly 21 months since the last push. This is the strongest evidence of currently stalled maintenance.
The package declares 16 runtime dependencies for a microframework, including several related HTTP components. This is a meaningful dependency surface, but the signal does not show an inherently excessive or unmanaged profile.
The package has six releases since November 2020, but none in the last 12 months; its latest release was about 21 months ago. This materially raises maintenance and abandonment concerns.
Both workflows were analyzed successfully with no untrusted checkouts, script injection, or high-confidence audit findings. However, all six action references are unpinned, a moderate reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2.0|^3.0 | — | — |
psr/container Version ^1.0|^2.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1|^2.0 | — | — |
httpsoft/http-cookie Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.