The package includes tests, an MIT license, and a clear README, which support adoption. Its repository has no security scanning or security policy, leaving maintenance and issue response less transparent.
48%
Total Score
25
100
79
83
The latest release was about 7 years ago, with no releases in the last 12 months; only five releases exist overall. This strongly raises abandonment risk despite the package having a stable release line.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since the latest registry release. The repository is not archived, but that does not compensate for absent recent activity.
There were no new or closed issues or pull requests in the last month, while one issue and one pull request remain open. This suggests little current maintenance activity.
Composer is used for builds, but no security scanning tools were detected. Build tooling supports reproducibility, while the missing scanning adds a modest hygiene gap.
The repository has no security policy, which reduces transparency for reporting and handling security issues. This is a secondary concern alongside the stronger evidence of inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.4 | — | — |
php-http/httplug Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.