The package has extensive consumer documentation, no install-time scripts, and a small runtime dependency set. Its license file is present, but it identifies Apache-2.0 while the manifest declares MIT; the repository also lacks a security policy.
78%
Total Score
83
100
88
83
A license file is present, but it identifies Apache-2.0 while the manifest declares MIT. The package is licensed, yet the mismatch requires legal clarification.
All 59 recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership partly offsets that risk because maintenance can potentially be handed off, but no second recent contributor is shown.
Composer is used for the build, which fits the package ecosystem. No repository security scanning tools were detected, leaving a modest security-process gap.
The repository has no published security policy. This weakens vulnerability-reporting transparency, though it does not outweigh the strong release and commit activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
symfony/polyfill-mbstring Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.