The package has had no release in more than six years and the repository shows almost no adoption or security process. Its matching repository, clear README, stable version, and lack of install scripts reduce uncertainty but do not offset the maintenance risk.
38%
Total Score
50
100
67
83
Only two releases were published, both in December 2019, with none in the last six years; this is strong evidence of abandonment risk.
No declared license, license file, or repository license file was detected, leaving the legal terms for reuse unclear.
The package is backed by an individual repository owner rather than an organization, so the small maintainer footprint is more significant.
The repository has zero stars and forks and one watcher, indicating little external adoption; popularity is supporting evidence rather than decisive on its own.
Composer is used for builds, but no security-scanning tool is configured, leaving repository-level security hygiene limited.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yangkai/request Version * | — | — |
yangkai/response Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.