Its Apache-2.0 licensing and test coverage are reassuring. Organization backing is present, but the release is too new to establish dependable maintenance or security practices.
68%
Total Score
75
88
83
This is the package's first release, published 0 days ago, so there is no release history or cadence demonstrating sustained maintenance.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the package is only 0 days old, this shows limited evidence rather than established abandonment.
Composer build tooling is present, but no security scanning tools were detected, leaving security review practices unverified for this new package.
The repository has no security policy, which is a transparency gap, although the package's very small and newly published project limits how strongly this weighs.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version 1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.