The package includes tests, a README, and release notes for v4.0.2, while its repository remains unarchived and matches the package. Its workflow uses two unpinned actions and lacks security scanning, so future maintenance deserves scrutiny.
62%
Total Score
75
88
75
The package has 14 releases since August 2014, but no releases in the last 12 months; the latest release was published roughly three years ago. This indicates materially reduced maintenance activity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the roughly three-year gap since the latest release. This raises abandonment risk.
Composer is used for the build, but the repository has no detected security-scanning tool. This is a modest transparency and maintenance gap rather than evidence of unsafe behavior by itself.
No security policy is present in the repository, leaving vulnerability reporting expectations unclear for a library that forwards HTTP requests.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or write permissions, but both of its two action references are unpinned. That is a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
relay/relay Version ~2.1.2 | — | — |
laravel/helpers Version ^1.6 | — | — |
guzzlehttp/guzzle Version ^7.7.0 | — | — |
laminas/laminas-diactoros Version ^3.1.0 | — | — |
laminas/laminas-httphandlerrunner Version ^2.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.