Usable with caveats: the package is actively released, licensed, non-deprecated, and backed by a matching repository with tests and release history. Recent repository activity is absent, and the repository lacks a security policy and explicit workflow token permissions.
72%
Total Score
50
100
100
80
Only one registry account has publish access. That is a modest resilience concern for a user-owned project, but registry access alone does not establish whether repository maintenance is actually limited.
The registry namespace and repository owner align, and the repository is owned by a user rather than an organization. This supports package identity but provides limited organizational continuity.
The repository recorded zero commits and zero active maintainers in the last three months. Although a release was published recently, the lack of recent commit activity weakens confidence in ongoing maintenance.
There are no open issues or pull requests, and no issue or pull-request activity in the last month. This is neutral for a small project but provides little evidence of an active support community.
The repository has no security policy, leaving the preferred process for reporting vulnerabilities and handling security issues undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.