Clear documentation, tests, licensing, and a recent release make the package straightforward to evaluate. Its small release history, single maintainer, and lack of security policy leave less evidence of sustained maintenance.
68%
Total Score
50
88
75
Only one registry maintainer is listed. Because the repository is user-owned rather than organization-backed, this leaves limited visible publishing redundancy.
The registry namespace and repository owner match, but ownership is an individual account rather than an organization. This supports identity consistency while offering limited evidence of broader project backing.
The package has four releases over about seven years, with a median interval of about 787 days, although one release occurred in the last 12 months. This supports continued availability but suggests an infrequent maintenance cadence.
There were no commits and no active maintainers in the last three months. The recent release provides some compensating evidence, but the current lack of development activity weakens confidence in ongoing maintenance.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.