The README, tests, MIT license, and focused dependency set make integration relatively clear. Organization backing and a clean workflow audit help, but supply-chain hygiene remains incomplete.
52%
Total Score
75
67
50
This package has only one release, published about 2 years 11 months ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long pause since its only release. No provided signal shows recent development to compensate.
The linked repository has no security policy and no security-scanning tools were detected. This is a transparency and maintenance gap, though it is less severe than abandonment evidence.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 4 of its action references are unpinned, leaving avoidable dependency-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client-implementation Version * | — | — |
psr/http-factory-implementation Version * | — | — |
psr/http-message-implementation Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.