Usable with caveats: it has a clear license, focused files, documentation, tests in the source repository, and organization backing. However, this is a brand-new release with no established release or commit history, so its long-term maintenance is not yet proven.
68%
Total Score
83
100
83
90
The package is 0 days old with only one release and no established release interval. That leaves no track record for maintenance consistency or release stability.
There were no commits or active maintainers in the preceding three months, although the repository was pushed on the release date. Because the project is newly published, this primarily reflects lack of history rather than proven abandonment.
The repository has zero stars, forks, and watchers. For a brand-new, narrowly scoped package this is limited supporting evidence rather than a severe concern, but it provides no external adoption signal.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap for a library intended for application integration.
No security policy was found in the repository. This is a transparency gap, though the small, newly published package has not yet demonstrated a history requiring formal vulnerability-reporting guidance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.53 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.