The repository is small and has no tests or security policy, while its MIT license and matching source repository provide useful transparency. Pin 3.0.1 and verify compatibility before relying on it.
58%
Total Score
75
81
75
The package includes a README, but it is only 25 characters long and the repository has no tests or changelog. Missing tests and changelog are normal packaging practice here; the extremely limited consumer documentation is the material gap.
The package has only 4 releases since April 2018, with no release in the last 12 months and a median interval of about 916 days. This indicates a slow maintenance cadence, though the latest release is still relatively recent.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, with the last push nearly two years ago. That is meaningful abandonment risk for a library dependency.
Composer is used for the build, which is appropriate for a Packagist package, but no security-scanning tooling is configured. This is a modest maintenance and supply-chain hygiene gap.
No security policy is present in the linked repository. This does not establish a security problem, but it reduces transparency about how dependency issues should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
polus/router Version ^3.0 || dev-main | — | — |
nikic/fast-route Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.