Organization backing, repository tests, release notes, and Dependabot provide solid support. The repository lacks a security policy and its workflows do not declare top-level permissions, while recent activity is light.
82%
Total Score
75
100
100
75
Only two commits were made in the last three months, so recent development volume is light, though two maintainers were active and the package released during that period.
There were no new issues or closed issues in the last month, with only one pull request merged; this indicates limited recent interaction but not abandonment by itself.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Both workflows omit top-level token permissions. No workflow declares top-level write access, but explicit least-privilege permissions are still absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0|^2.0|^3.0 | — | — |
php-http/httplug Version ^2.2 | — | — |
psr/http-message Version ^1.0|^2.0 | — | — |
php-http/discovery Version ^1.12 | — | — |
php-http/cache-plugin Version ^1.7.1|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.