The MIT license, usable README, and matching repository make it transparent to inspect. Its small dependency surface is reassuring, but current platform changes and defects may go unanswered.
43%
Total Score
50
100
86
88
Only one registry account can publish releases, and the repository owner is an individual rather than an organization; this creates a thin maintainer base alongside the inactive project.
The package has had only two releases, with no release in more than eight years; this is strong evidence of abandonment despite a stable 1.1.0 version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving maintenance capacity unclear.
Composer build tooling is present, but no security-scanning tooling is reported; this is a minor hygiene gap rather than a standalone adoption blocker.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent; the small, inactive project does not compensate for that gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
singiu/http-php Version ^1.0.0 | — | — |
paragonie/random_compat Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.