The source repository remains available and includes tests, a changelog, and security scanning, but the package has not been released since August 2021 and shows no commits in the last three months. All 12 workflow actions are unpinned, and no security policy is published.
62%
Total Score
75
50
94
75
The package has 15 runtime dependencies, including several HTTP abstraction packages. This is a relatively broad dependency surface and adds maintenance exposure, but it is consistent with the client's stated architecture.
The package has 24 releases over roughly 9 years, but the latest release was in August 2021 and there were no releases in the last 12 months. This is a meaningful freshness concern for a dependency.
There were no commits and no active maintainers in the last three months. This reinforces the stale release history and lowers confidence in active maintenance.
Two issues and two pull requests remain open, with no new or closed items in the last month. This indicates limited current issue throughput but is not, by itself, evidence of abandonment.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it is less severe than evidence of unsafe build behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.7 || ^4.0 | — | — |
beberlei/assert Version ^2.8 || ^3.0 | — | — |
myclabs/php-enum Version ^1.6 | — | — |
php-http/httplug Version ^1.1 || ^2.0 | — | — |
php-http/message Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.