The repository includes tests, a changelog, a security policy, and a matching package reference. Its dependency set is substantial, but the project shows no recent maintenance or security scanning.
42%
Total Score
33
71
100
This package has had only one release, published about 4 years and 5 months ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the long time since the last push, this is strong evidence of inactive maintenance.
The repository is owned by a personal GitHub account rather than an organization, so there is no organizational backing to compensate for the single registry maintainer and inactive project.
There were no new or merged pull requests and no issue activity in the last month. The absence of visible recent collaboration adds to the maintenance concern, though the open-issues count is unknown.
Composer build tooling is present, but no security-scanning tooling was detected. That is a modest transparency and maintenance weakness, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.6 | — | — |
myclabs/php-enum Version ^1.7 | — | — |
php-http/httplug Version ^2.1 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
paquettg/string-encode Version ~1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.