Its tiny PHP footprint and single runtime dependency limit adoption complexity. The repository matches the package and has clear usage documentation, but ongoing project oversight appears limited.
58%
Total Score
50
100
83
83
The package and repository are owned by the same individual account, providing direct ownership alignment but no organizational backing to broaden maintenance capacity.
The package has only 3 releases over roughly 7 years, with no releases in the last 12 months and the latest release in January 2022. This indicates slow maintenance for a dependency, though the small scope may reduce update needs.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. That weakens evidence of active maintenance.
Composer is used for builds, but no repository security-scanning tool was detected. This is a modest transparency and hygiene gap, not a severe risk for this small package.
The repository has no published security policy, leaving vulnerability-reporting expectations unspecified. This is a minor transparency concern for a package that processes request headers.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.