Usable with caveats: the package is licensed, includes tests and documentation, and is not deprecated or archived. However, it remains an early work-in-progress with no registry release in over a year and no commits in the last three months, so avoid it for critical production use without validating maintenance needs.
58%
Total Score
50
100
78
88
The registry namespace and repository owner differ and the repository is user-owned, but the repository name matches the package and its README explicitly references the package. This provides some provenance support while leaving backing relatively thin.
Only three releases were published, all within about 12 days, followed by no release in the last 12 months. That limited and stalled release history lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the last three months. Combined with the lack of recent registry releases, this indicates currently stalled development.
The repository has only 1 star, 3 forks, and 1 watcher. Low adoption is supporting caution rather than a decisive health failure, especially because the package is small and specialized.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance gap, though not severe enough to make the package unfit by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
psr/http-message Version ^1.0|^2.0 | — | — |
bakame/http-structured-fields Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.