Healthy and suitable to depend on for its narrow role as stable PSR-17 interfaces, with clear licensing, minimal dependencies, and organization-backed source. Maintenance is quiet: there have been no registry releases in over two years and no repository commits in the last three months, though the package is mature and not deprecated.
78%
Total Score
75
100
89
83
The package has existed since 2018 with four releases, but it has had no registry release in the last two years. For a small, stable interfaces-only package this is a maintenance caution rather than evidence of abandonment by itself.
There were no commits and no active maintainers in the last three months. This lowers confidence in near-term maintenance, but the package's narrow, mature interface scope partly offsets the concern.
Composer is used for the build, which matches the package ecosystem, but no security scanning tools were detected. The missing scanning is a transparency gap, not a severe risk for this small interfaces-only package.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a modest transparency gap for a small standards-interface package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.