Usable with caveats: the package is mature, licensed, tested in its repository, and not deprecated or archived. However, it has had no registry release in about 18 months and no commits in the last 3 months, so maintenance appears quiet.
68%
Total Score
67
100
94
80
The package has been established since 2017 with 24 releases, but it has had no registry release in the last 12 months; the latest release was about 18 months ago. This is a meaningful maintenance concern, though not evidence of abandonment by itself.
The repository recorded zero commits and zero active maintainers in the last 3 months. That recent inactivity lowers confidence in prompt fixes, although the repository was pushed more recently and the assessed release has documented changes.
Only four issues and one pull request are open, but there were no new or closed issues or pull requests in the last month. This supports the picture of a quiet project rather than active ongoing maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is not severe enough to make the package unfit on its own.
None of the four workflows declares top-level token permissions, so their permissions are less explicit than ideal; no workflow requests top-level write access, which limits the severity of this hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.