A license is present, the repository is intact, and this release includes detailed notes with repository tests. The project lacks a security policy, and both workflows grant broad write permissions; the single-person project backing also limits resilience.
67%
Total Score
67
94
50
Post-install and post-update scripts add installation-time execution surface and warrant some caution for dependency adoption, though they are not evidence of abandonment by themselves.
The repository is owned by an individual account rather than an organization, so there is no demonstrated organizational redundancy behind maintenance.
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful sign of currently paused development even though a recent release exists.
The project uses Make and Composer, but no security-scanning tooling was detected, leaving a governance and maintenance gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2 || ^3 | — | — |
react/http Version ^1.11.0 | — | — |
react/cache Version ^1.2.0 | — | — |
react/promise Version ^2.8 || ^3.3.0 | — | — |
psr/http-message Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.