The artifact is licensed and its dependency set is small and explicit. Maintenance has gone quiet, and the repository has no security scanning or policy; organization backing offers some continuity.
66%
Total Score
75
100
86
50
The package has six releases since April 2018, but none in the 12 months before collection; the latest release was over a year ago, which suggests slowing maintenance.
There were no commits and no active maintainers during the last three months, consistent with the release gap and raising abandonment concern.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful repository hygiene gap.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.