The repository is small but clearly structured, tested, licensed, and backed by an organization. Recent release activity is followed by no commits in the last three months, while unpinned workflow actions and no security policy leave moderate maintenance and build-hygiene concerns.
63%
Total Score
75
88
67
The package is young at 107 days, with three releases and a median interval of about 6 days; this shows initial activity but not a long maintenance record.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful warning for a package with only about three months of history.
Composer is used for builds, but no security scanning tooling was detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, so consumers have no documented path for reporting vulnerabilities or understanding security handling.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but both action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
relay/relay Version ^2.1 | — | — |
georgeff/kernel Version ^1.6 | — | — |
nikic/fast-route Version ^1.3 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.