The package is well documented, has a focused dependency set, and avoids install-time scripts. Its small, inactive repository and license mismatch warrant pinning this exact release and checking licensing with the publisher.
55%
Total Score
75
100
78
83
The manifest declares MIT and license files are present, but the detected artifact license is Apache-2.0, creating an unresolved licensing inconsistency.
Eight releases appeared in the last 12 months, but they were concentrated in roughly 11 days and no newer release followed, weakening evidence of ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the roughly 10-month release silence and raising abandonment risk.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity alone is not decisive for a small package.
Composer is used for the build, but no security scanning tools were detected, leaving a modest repository-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.