Clear licensing, tests, documentation, and release notes make the package straightforward to evaluate and maintain in an application. The small repository and organization backing help offset the quiet recent development and limited workflow security hygiene.
76%
Total Score
75
100
94
75
There were no commits and no active maintainers in the three months before collection. The recent release partly offsets this, but the quiet interval still leaves some maintenance risk.
Two issues and one pull request remain open, with no issues or pull requests closed in the past month; this is a modest sign of limited current responsiveness.
Composer build tooling is present, but no security scanning tool is configured, leaving a security-hygiene gap in the repository.
The repository has no published security policy, making the process for reporting and handling vulnerabilities less transparent.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all three action references are unpinned, so workflow supply-chain reproducibility is weaker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ~1.4 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.