Usable with caveats: it is actively maintained, licensed, tested in the repository, and has a clear stable release history. Maintenance depends on one contributor and the repository has no security policy, so consider the limited review capacity before adopting it broadly.
72%
Total Score
75
50
94
83
Eleven runtime dependencies, including several related packages from the same publisher, increase the dependency surface and warrant routine compatibility review, but do not by themselves indicate abandonment.
The repository is owned by an individual user rather than an organization, so there is no provided organizational backing to offset the concentrated contributor base.
All 28 commits in the last three months came from one contributor, leaving limited independent review and a meaningful continuity risk for this user-owned project.
Composer build tooling is present, but no security-scanning tooling was detected, leaving vulnerability detection less explicit.
No repository security policy was found, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version 1.0.* | — | — |
psr/http-factory Version 1.1.* | — | — |
psr/http-message Version 2.0.* | — | — |
juanchosl/exceptions Version 1.0.* | — | — |
juanchosl/validators Version 1.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.