The matching repository includes tests, a changelog, and a README, while dependencies are small and install-time scripts are absent. The stable MIT release is straightforward to inspect, but maintenance appears abandoned and project activity is minimal.
43%
Total Score
50
100
72
88
This is the package's only release, published over six years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency expected to receive maintenance.
There were no commits and no active maintainers in the last three months. Combined with the single historical release, this indicates very limited current maintenance capacity.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no external sign of adoption or active community support.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning is a modest transparency gap, while the build setup itself is positive.
The repository is not marked archived, but it was last pushed over six years ago. The stale activity still weighs heavily against the package despite its unarchived status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-server-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.