The package includes tests, a useful README, and security scanning. Its security policy is missing, and all recent work comes from one contributor, leaving limited backup if maintenance stops.
68%
Total Score
50
100
89
75
The repository is owned by an individual user rather than an organization, so the single-maintainer and bus-factor concerns are not offset by visible organizational backing.
The package is only 60 days old but has 17 releases, with a median interval of about 7 hours; this shows active early development but little long-term history.
One contributor made all 13 recent commits, creating a high single-maintainer dependency and increasing continuity risk.
There were 13 commits in the last three months, showing recent work, but the activity is concentrated in one maintainer.
The repository has no stars, forks, or watchers. This is weak supporting evidence, but popularity alone does not determine the health of a young package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.