The documented roadmap still lists core features, validation, tests, and benchmarks as unfinished, and the project has no security policy. The MIT license, README, and repository tests provide useful transparency, but do not offset the maintenance risk.
40%
Total Score
0
100
69
75
The package has had only one release, first published about 6 years and 9 months ago, with no releases in the last 12 months. This is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last 3 months, consistent with the repository's last push being about 6 years and 9 months ago. This materially increases abandonment risk.
The package includes a README and the repository has tests, but the README explicitly lists cache support, unit and functional tests, benchmarks, all SLS methods, and request validation as unfinished. The GitHub release confirms release transparency for this version, but not implementation completeness.
The repository uses Composer, which supports reproducible project builds, but it has no security scanning tools. That is a maintenance and transparency gap for a package handling service requests.
No security policy was found in the linked repository. This weakens the project's disclosure and response process, although it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.