MIT licensing, a clear README, tests, and a small direct dependency set make integration straightforward. The repository is not archived and the package is not deprecated, but its low adoption and lack of security scanning reduce confidence for security-sensitive use.
53%
Total Score
50
100
83
75
One registry publisher is consistent with a user-owned project, but it also indicates limited publishing capacity when combined with the absence of recent activity.
The package has 11 releases, but none in the last 12 months and the latest release was nearly two years ago. This is a meaningful maintenance concern despite the earlier rapid release cadence.
There were no commits and no active maintainers in the last three months, consistent with the long gap since the last release. This raises abandonment risk.
The repository has one star, no forks, and one watcher. Low adoption is supporting caution about project maturity, but popularity alone does not make a small package unsafe.
Composer is used for builds, but no security scanning tools are configured. That weakens repository hygiene, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version >=5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.