Healthy and reasonable to adopt, with a small maintenance caveat. It is a stable, licensed package backed by an active organization, but the repository recorded no commits or active maintainers in the last three months and some workflows lack explicit permissions.
78%
Total Score
67
100
94
83
The repository recorded zero commits and zero active maintainers during the last three months. Recent release activity and a push within the last three days partly offset this, but the lack of sustained contributor activity remains a maintenance caution.
Only one issue and two pull requests are open, with no new or merged items in the last month. The quiet queue is not a severe concern, but it offers limited evidence of active issue handling.
Composer build tooling is present, but no security scanning tools were detected. The build setup is adequate, while the missing scanning automation is a modest transparency and maintenance gap.
Two workflows lack top-level token permissions, and one declares write access. Although no dangerous workflow behavior was detected, more explicit least-privilege declarations would improve repository hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0.2 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
fig/http-message-util Version ^1.1 | — | — |
laminas/laminas-escaper Version ^2.10.0 | — | — |
psr/http-server-middleware Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.