Healthy and suitable to use, with a small maintainer-base caveat. It is actively developed, clearly packaged, tested, licensed, and not deprecated or archived; maintenance depends entirely on one contributor and the repository lacks security scanning and a security policy.
78%
Total Score
75
100
88
80
The package is young at 114 days and has only three releases, but releases are still occurring, including the assessed release within the latest collection period.
One contributor made all 183 recent commits, leaving the project exposed to a single-person maintenance failure; the individual-owned repository provides no organizational handoff evidence.
The repository recorded 183 commits in the last three months, demonstrating very active development, although all activity came from one maintainer.
Composer build tooling is used, but no security-scanning tool was detected, leaving a useful supply-chain hygiene gap.
No security policy was found in the repository, which weakens vulnerability-reporting transparency for a reusable library.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/cache Version ^3.0 | — | — |
psr/container Version ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.