The repository includes tests, a clear README, a matching license, and no install-time scripts. Its small footprint, absent security tooling, and limited release history provide less evidence of long-term support.
59%
Total Score
50
79
75
The package has only two releases, both published about five months ago, with no later release activity. This is limited evidence of ongoing maintenance for a package still at version 0.1.1.
There were no commits from any active maintainer in the past three months, leaving limited evidence that the project is being maintained after its initial release period.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy, so there is no documented channel or process for handling vulnerabilities. This modestly lowers project transparency.
Version 0.1.1 is below a stable major release, so its API and behavior may still change. No prerelease labeling partly reduces that concern, but it does not establish maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nih/router Version ^0.2.0 | — | — |
nih/container Version ^0.1.3 | — | — |
nih/http-kernel Version ^0.1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.