Documentation, tests, changelog, and licensing are all in place. The small public footprint and missing security policy add modest uncertainty for a package with no recent repository activity.
62%
Total Score
75
83
83
Only 3 releases over 422 days, with a median interval of about 148 days, indicates a deliberate but relatively slow release cadence; the latest release is recent enough to offset abandonment concerns.
The repository recorded 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance concern despite a release on May 15, 2026.
The repository has 1 star, 0 forks, and 0 watchers, providing little evidence of broad external use or review. This is supporting caution rather than a verdict on a small organization-backed package.
The repository uses Composer build tooling, but reports no security scanning tools. The missing scanning is a minor hygiene concern, outweighed by the package's documentation and tests.
The linked repository has no security policy, reducing transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
psr/container Version ^2.0 | — | — |
psr/http-message Version ^2.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
webonyx/graphql-php Version ^15.32 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.