The source includes tests and a changelog, and the package is MIT-licensed without install-time scripts. Its zero recent commits and lack of releases for over 12 months make future fixes uncertain, while all six workflow actions are unpinned.
43%
Total Score
0
100
69
67
The package is 636 days old, has 11 releases, and has had no releases in the last 12 months. That long publishing gap is a meaningful maintenance concern.
There were no commits and no active maintainers in the last 3 months. Combined with the old last push, this is strong evidence that maintenance has stalled.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible adoption provides no additional maturity signal.
Composer is used for the build, but no security scanning tools are detected. The build setup is present; the missing scanning is a modest transparency gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself show that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0.1 | — | — |
psr/http-message Version ^1.0.1 | — | — |
php-http/discovery Version ^1.15.2 | — | — |
psr/http-client-implementation Version ^1.0.1 | — | — |
psr/http-factory-implementation Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.