The package is narrowly scoped, clearly documented, and backed by an organization. It is brand new with only one release and no recorded commit activity, so its maintenance track record is not yet established; the absence of security scanning adds a smaller concern.
72%
Total Score
75
100
89
88
This is a new package with one release, first and latest published on the same day, so there is not yet a track record of sustained maintenance or release quality.
No commits and no active maintainers were recorded in the last three months. Because the repository and release are newly created, this is partly explained by age, but it still leaves no established maintenance evidence.
The repository uses Composer, matching the package ecosystem, but no security scanning tools were detected. That is a modest transparency and assurance gap, not evidence of an unsafe release by itself.
The repository has no security policy. For a small type-definition metapackage this is a minor maturity gap, though the package's narrow scope limits its impact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/psr-http-client-impl Version ~1.0.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.