It is a small, clearly scoped package with tests, a matching source repository, a stable version, and no install scripts. Its single release and zero recent commits leave too little maintenance history to support a stronger assessment.
62%
Total Score
75
100
83
88
The package was released once, on the same day it was assessed, so there is no release track record yet; this limits evidence of sustained maintenance.
There were zero commits and zero active maintainers in the last three months, but the repository itself is newly created, so this is limited evidence rather than proof of abandonment.
The repository has no stars, forks, or watchers. This is weak supporting evidence only and does not outweigh the matching repository and project backing.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tools were detected; that is a modest transparency gap.
No repository security policy was found, leaving vulnerability-reporting guidance unspecified for consumers and maintainers.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
php-http/discovery Version 1.20.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.