The codebase is small and clearly documented, with tests and a matching MIT license. No repository commits or package releases have appeared for over 10 years, making future fixes and compatibility work unlikely.
38%
Total Score
0
75
75
The latest release was on April 12, 2016, with no releases in the last 12 months; this long gap is strong evidence of abandonment for a dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's over-10-year release gap and leaving little evidence of ongoing maintenance.
The repository uses Composer for its build tooling, but has no security-scanning tools; this is a minor hygiene gap rather than evidence that the release is unfit.
No security policy is present in the linked repository, reducing transparency for reporting and handling vulnerabilities; the long period without maintenance makes this gap more relevant.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.2.2 | — | — |
php-http/httplug Version ^1.0.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.