The MIT license, tests, and release notes provide useful transparency. Its single-user project has had no release or commit activity for nearly eight years, and the package is archived and abandoned.
8%
Total Score
0
40
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning that the release is no longer suitable as a maintained dependency.
The package has had no releases in nearly eight years; its latest release was December 27, 2018. This strongly indicates abandonment despite its earlier 12-release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the archive status and long release gap.
The linked repository is archived and was last pushed on December 27, 2018. An archived source project indicates active maintenance has ended.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though the stronger abandonment signals already determine the assessment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
tebe/http-factory Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.