The package includes clear consumer documentation, release notes, and repository tests, with a small dependency footprint. Limited security-process coverage and unpinned workflow actions reduce assurance, while recent publishing activity remains strong.
82%
Total Score
67
100
94
67
The repository and registry are owned by the same individual account, so the package has direct ownership continuity but no organizational backing shown by the collected evidence.
Recent commits are evenly split between two contributors, so activity is not concentrated in one person; the small contributor count still limits resilience.
Composer build tooling is present, but no security-scanning tool was detected, leaving less automated assurance for dependency and code risks.
The repository has no security policy, which weakens guidance for reporting and handling vulnerabilities but does not by itself indicate abandonment.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 6 of 6 action references are unpinned, reducing build reproducibility and supply-chain assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.