A clear MIT license, included tests, and no install-time scripts make the package straightforward to inspect and install. Its single publisher, one-star repository, and lack of activity for over seven years leave little evidence of ongoing support.
42%
Total Score
25
100
75
75
The package has had only two releases, with the latest published over seven years ago and no releases in the last 12 months. This is strong evidence of abandonment for a request library.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no update for over seven years.
Only one registry account has publishing access. The repository is organization-owned, which makes a short registry maintainer list less concerning, but the observed inactivity still leaves limited maintenance capacity.
The repository has one star, zero forks, and one watcher, providing very little evidence of community use or external support. Popularity is only supporting evidence, but it reinforces the maintenance concern.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a modest hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.