The package has a clear Apache-2.0 license, tests, and no install-time scripts. Its organization-backed repository is newly created, so there is not yet enough history to establish staying power.
61%
Total Score
75
100
88
83
The package has only one release and is less than one day old, so there is no release history or cadence demonstrating sustained maintenance.
There were no commits or active maintainers in the last three months, but the repository is newly created, so this is currently an unproven maintenance record rather than evidence of abandonment.
Composer is used as the build tool, but no security scanning tools were detected. For a newly published package this is a modest repository-hygiene gap.
The repository has no security policy. This limits disclosure transparency, though the package is small and newly established.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
fig/http-message-util Version 1.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.