The declared GPL-2.0+ license and modest runtime dependencies are clear. The organizational repository is active and unarchived, but ongoing assurance remains limited.
62%
Total Score
75
100
75
75
The package has no README, which makes a library harder to integrate. Missing tests and a changelog are not concerns here because they are not expected in the published artifact under these rules.
The package has four releases over about five years and two releases in the last 12 months, including a recent release; this shows activity but a relatively sparse cadence.
All three-month commit activity comes from one contributor. Organizational ownership offers some handoff capacity, but no second active contributor is shown.
Only one commit was made by one active maintainer in the last three months, which is weak evidence of ongoing maintenance despite the recent release.
Composer is used for builds, but no security scanning tool was detected, leaving a modest supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.