The package is clearly licensed, documented, tested in the repository, and uses Psalm for analysis. Its workflow leaves all three actions unpinned and lacks a security policy, while the tiny footprint offers little evidence of ongoing support.
58%
Total Score
0
70
50
This is the package's only release, published over five years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance, though a stable fork may not require frequent releases.
The repository recorded no commits and no active maintainers during the last three months, consistent with the absence of releases since June 2021. This is substantial abandonment risk for a dependency requiring future fixes.
The repository has zero stars and forks and only two watchers, indicating very limited external adoption. Popularity is supporting evidence rather than a verdict, but it provides little additional confidence in long-term support.
No repository security policy was found. This reduces transparency about vulnerability reporting and response, although the presence of Psalm provides partial compensating security practice.
The single workflow was fully analyzed without dangerous triggers, sinks, or audit findings, but all three action references are unpinned. That leaves the build exposed to unexpected action changes and is a moderate hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
ralouphie/getallheaders Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.