HTTP response freshness testing
78%
Total Score
63
100
83
100
The package has existed since 2012 with 14 releases, but it has had no release in the last two years, indicating slower maintenance and potentially stale published code.
All recent commit activity comes from one contributor, creating concentration risk; the risk is partly offset by the repository being owned by the jshttp organization.
There was one commit in the last three months from one active maintainer, which is evidence of continued activity but also points to a slow maintenance pace.
The repository has only one open issue and received one new pull request in the last month, but no pull requests were merged in that period, so recent maintenance appears limited.
No type declarations are published, which reduces editor and type-checking support, but this is a small consumer-ergonomics gap for a compact JavaScript utility rather than a maintenance risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-16119 fresh is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 0.5.2. | 0.0.0 - 0.5.2 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.