It has clear MIT licensing, a matching source repository, and a changelog. The single registry maintainer and absent security policy limit resilience and transparency, while the organization backing provides some compensation.
62%
Total Score
67
88
50
Only one account has registry publish access, which reduces publishing redundancy. The organization-owned repository provides some backing, so this is a resilience concern rather than a severe risk.
The package has had 5 releases since July 2023, but none in the last 12 months; the latest release was in February 2025. This indicates a meaningful maintenance slowdown for a library dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The recent release provides some evidence of prior maintenance, but current activity is absent.
Composer is used as the build tool, but no security-scanning tools were detected. The standard build tooling is positive, while the missing scanning coverage is a modest hygiene gap.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This lowers transparency but does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webservco/http Version ^1 | — | — |
psr/http-message Version ^2 | — | — |
webservco/emitter Version ^1 | — | — |
webservco/application Version ^1 | — | — |
psr/http-server-handler Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.