The package is clearly identified, licensed, and backed by an organization, with no install-time scripts or workflow hazards. Its small footprint helps, but there is little evidence of an active support process for new adopters.
40%
Total Score
100
69
83
The last release was on August 30, 2016, nearly 10 years ago, with no releases in the last 12 months. This is strong evidence that maintenance has stopped.
The repository has 1 star and 0 forks, providing little evidence of broad adoption or an active contributor community. Low popularity is supporting evidence rather than proof of poor quality.
Composer is used for builds, but no security scanning tool is present. This is a transparency and maintenance gap, though it is less significant than the long release hiatus.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.3.1 is not a stable major release, which adds some maturity risk, although it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thruster/promise Version ^1.0 | — | — |
thruster/http-router Version ^1.1 | — | — |
thruster/http-message Version ^1.1 | — | — |
thruster/http-middleware Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.