The package has solid tests, release notes, licensing, and a focused dependency set. Recent commit activity is absent, and all three workflow actions are unpinned, leaving maintenance and build-reproducibility concerns.
68%
Total Score
75
100
89
83
The package has 23 releases over roughly seven years, but none in the last 12 months; the long release gap lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful sign of currently limited maintenance activity.
There is one open issue and no issue or pull-request activity in the last month, providing little evidence of active community maintenance.
Composer and Make are used for project tooling, but no security scanning tool is reported; the missing scanner is a modest transparency gap rather than a severe health risk.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent for a library used in HTTP integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.