The source includes a matching license, tests, release notes, and dependency automation. Those safeguards do not provide an active path for fixes or new releases.
12%
Total Score
0
57
Packagist marks the entire package as abandoned, with no replacement identified. This is a severe adoption and maintenance warning.
The package has 14 releases since January 2023 but none in roughly 17 months, indicating that release activity has stopped.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the abandonment risk.
The linked repository is archived, even though it was last pushed in June 2025. Archived source is a severe abandonment risk for a dependency.
All six workflows were analyzed with no untrusted checkouts or script injection, but all nine action references are unpinned and high-confidence secrets-inherit findings appear in several workflows. These are meaningful hygiene and credential-scope concerns, not the primary reason for the score.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^2.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.