This is a healthy, actively maintained release with a substantial history: 42 releases over roughly 4 years, 21 releases in the last 12 months, and a stable non-prerelease version. The repository is active, unarchived, correctly associated with the package, backed by an organization, and includes tests, build tooling, Dependabot, a security policy, and generally safe workflows. The main concern is concentrated recent maintenance: all 7 commits in the last 3 months came from one contributor, although organizational backing and four merged pull requests in the last month provide some mitigation. The package is therefore a reasonable dependency, with normal single-maintainer continuity risk rather than a strong abandonment signal.
86%
Total Score
88
100
100
90
Recent activity is fully concentrated in one contributor: one active maintainer made all 7 commits in the last 3 months. This is a genuine continuity concern, but the organization-owned repository provides some ability to hand off maintenance.
Both workflows declare top-level permissions, including one read-only workflow; one auto-assign workflow has top-level write permissions, which is broader than ideal but is limited to a known automation workflow and is not by itself a severe health risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^2.0 | — | — |
tiny-blocks/time Version ^2.6 | — | — |
tiny-blocks/mapper Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.