The package is clearly structured, documented, tested, and has a focused dependency set. Security governance is limited, with no policy or scanning, and its maintenance record is too short to establish ongoing support.
64%
Total Score
50
100
89
75
This is the package's first release, published today, so there is no release history or cadence demonstrating sustained maintenance. Its stable 1.0.0 version provides some maturity signal but cannot offset the lack of history.
There were no commits or active maintainers in the three-month activity window beyond the initial publication, so ongoing maintenance capacity is unproven. The repository's same-day push is consistent with a new project but does not establish continuity.
Composer build tooling is present, but no security scanning tools are configured. The tests and static-analysis configuration compensate for some quality concerns, not the missing security coverage.
The repository has no security policy, leaving vulnerability reporting and response expectations unspecified. The package's tests and license improve transparency but do not replace security-response guidance.
No GitHub Actions workflows were present, so there were no workflow risks to identify and no audit failures. This also provides no automated CI or release assurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.