The small interface-only artifact has a clear README and minimal runtime dependency. Its build setup is present, but the source does not identify the package in its README and lacks security scanning and a security policy.
12%
Total Score
0
38
83
Packagist marks the entire package as abandoned and names appserver-io-psr/http-message as its replacement. This is a direct indication that developers should not start depending on this package.
The package has only one release, published about 12 years ago, with no releases in the last 12 months. That strongly indicates the dependency is no longer maintained.
The linked repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's long release inactivity and increasing abandonment risk.
The linked repository name does not match the package name, and its README does not mention the package. Although organization-backed repositories can serve multiple packages, this combination makes package ownership and provenance less transparent.
The repository has no security policy. For a small interface package this is a secondary gap, but it provides no documented path for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.