The repository is organized and the package is licensed, tested, and backed by an organization. Its single release provides no maintenance history, so pinning it carries more uncertainty than an established dependency.
64%
Total Score
75
100
88
88
This is the package's first release, published less than a day ago, so there is no release cadence or maintenance track record yet. The caution is partly offset by the matching repository and organization backing.
No commits or active maintainers were observed in the last three months. Because the package was released less than a day ago, this mostly reflects the absence of history rather than proven abandonment, but it limits confidence.
The repository uses Composer, but no security scanning tool was detected. For a newly published package this is a transparency and hygiene gap, though it is not severe on its own.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the small package scope and clear licensing provide some compensating structure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
php-http/httplug Version 2.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.