Clear licensing, tests, and dependency discipline add useful confidence. The small contributor base and lack of a security policy leave modest maintenance and disclosure risk.
82%
Total Score
83
100
94
75
Two contributors are active, but one accounts for about 89% of recent commits, leaving maintenance concentrated despite organization backing.
No repository security policy was found, leaving vulnerability-reporting and response expectations less transparent for adopters.
The release is not marked prerelease, although the v0.x major version signals a less mature compatibility promise than a stable major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.