The README, tests, MIT license, and matching organization repository make the package easier to evaluate. Its missing security policy leaves less formal support evidence.
38%
Total Score
50
75
83
The package has only three releases, with none in the last nine years and the latest release in January 2017. This is strong evidence of abandonment risk despite a previously regular release interval.
There were no commits and no active maintainers in the last three months, consistent with the roughly nine-year gap since the last repository push. This materially increases abandonment risk.
One issue and one pull request remain open, with no new or closed activity in the last month. This suggests limited ongoing project attention, though the small totals temper the concern.
The repository uses Composer, but no security scanning tooling was detected. The build setup is appropriate, while the lack of scanning is a modest hygiene gap.
No repository security policy was found, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ~1.0 | — | — |
dflydev/fig-cookies Version ~1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.