The package has a clear MIT license, tests, a changelog, a substantial README, and read-only workflow permissions. Maintenance evidence is thin: it has only one release, no commits in three months, one maintainer, no security scanning, and all seven workflow actions are unpinned.
58%
Total Score
50
100
83
67
One registry maintainer is publishing the package. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of a broader maintainer base to compensate for the single-person dependency.
The repository is owned by an individual user, not an organization. That is consistent with a small package but offers less visible institutional backing for continuity.
This is the only release, published 233 days ago, so there is no demonstrated release cadence or evidence of continued delivery. That makes long-term maintenance uncertain for a library dependency.
There were zero commits and zero active maintainers during the last three months. For a package released only once, this is meaningful evidence that ongoing maintenance has not yet been demonstrated.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external adoption signal to offset the limited maintenance history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.