The package is clearly identified, licensed, documented, and backed by repository tests. Its maintenance activity stopped about six years ago, and the repository has no security scanning or policy, increasing the risk of depending on an abandoned library.
42%
Total Score
50
100
81
88
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the release history, this indicates prolonged inactivity and raises abandonment risk.
The package has 22 releases since November 2018, but none in the last 12 months and the latest release was in July 2020. This long release gap is a substantial abandonment concern.
There are no open issues or pull requests, and no issue or pull-request activity in the last month. With no recent commits or releases, this is consistent with an inactive project rather than active stability.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these low adoption indicators provide little external evidence of ongoing community support.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest transparency and maintenance gap, not evidence of a security verdict by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hhvm/hsl Version ^4.0 | — | — |
hhvm/hhvm-autoload Version ^3.0 | — | — |
hhvm/hsl-experimental Version ^4.50 | — | — |
ytake/extended-hack-http-request Version ^0.1.2 | — | — |
facebook/hack-http-request-response-interfaces Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.