The MIT license, README, and small dependency set make the artifact understandable. Its post-update install script adds avoidable operational risk, and the available maintenance evidence does not support continued use.
15%
Total Score
100
50
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the release should not be expected to receive maintenance or support.
This is the only release, published about 3 years and 7 months ago, with no releases in the last 12 months. That strongly suggests an immature or abandoned dependency.
The package runs a post-update-cmd lifecycle script during dependency updates. Install-time scripts increase operational exposure and are a caution when the package is already abandoned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.