Clear documentation, tests, licensing, and a stable release history make the package easy to evaluate. Maintenance is concentrated in one contributor, with minimal recent activity and unpinned workflow actions.
78%
Total Score
63
100
94
75
Only one registry account can publish the package. That is consistent with an individually owned project, but it leaves limited publishing redundancy when combined with the repository's concentrated activity.
All recent commits came from one contributor, giving the project a single-person maintenance dependency with no demonstrated recent handoff capacity.
The repository recorded only one commit in the last 3 months from one active maintainer. The recent release offsets abandonment concerns somewhat, but the current maintenance pace is thin.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy, so there is no stated channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
psr/http-message Version ^2.0 | — | — |
guzzlehttp/uri-template Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.