The MIT license and matching source tree make its contents clear, and it has no install-time scripts. Its short README and absent security policy offer little additional assurance.
8%
Total Score
42
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption and maintenance warning.
The package has only 2 releases, both published about 9 years ago, with no releases in the last 12 months. This strongly indicates abandonment.
The linked repository is archived and was last pushed about 9 years ago, showing that active maintenance has ended.
A README is present, but it is only 47 characters and the package has no tests or changelog. Missing tests and changelog are not inherently problematic for a published artifact, while the minimal documentation provides limited consumer guidance.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a secondary transparency gap alongside the much stronger abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
sheychen/inutils Version ^1.0 | — | — |
http-interop/http-factory Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.