The MIT license, README, repository tests, changelog, and release notes provide useful transparency for consumers. No commits or releases have appeared for over two years, while all four workflow actions are unpinned and no security policy is present.
62%
Total Score
50
88
83
The package has 11 releases over about 10 years, but none in the last 12 months and the latest release is from February 2024, indicating meaningful maintenance slowdown.
There were zero commits and zero active maintainers in the last three months, consistent with the broader lack of releases and raising abandonment risk.
Composer build tooling is present, but no security scanning tools are configured, leaving a modest repository hygiene gap.
The repository has no security policy, which weakens transparency about vulnerability reporting and response expectations.
The single workflow was fully analyzed with no audit findings or untrusted triggers, but all four action references are unpinned, reducing build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
php-http/discovery Version ^1.18 | — | — |
symfony/serializer Version ^6.4 || ^7.0 | — | — |
fig/http-message-util Version ^1.1 | — | — |
symfony/property-access Version ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.