The package includes extensive tests and has released six times in the last year. Its README is missing, repository naming does not clearly identify the package, and the project has no security policy or security scanning.
65%
Total Score
50
63
50
The package declares a proprietary license in its manifest, so it is licensed, even though no license file was detected. The declaration may impose adoption restrictions for developers expecting an open-source license.
The artifact contains tests and the repository also contains tests, which supports basic project maturity. The missing README weakens consumer documentation for a reusable library.
There were no commits and no active maintainers in the last three months. The recent release history partly compensates for this, but the current source-development silence remains a maintenance concern.
The repository name does not match the package name, and no README package mention was observed. That makes the ownership relationship less clear, although naming differences can occur for subpackages.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little external evidence of maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
beberlei/assert Version ^3.3 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.