Package Health

99designs/http-signatures-guzzlehttp

Sign and verify HTTP messages with Guzzle 6

Latest 2.0.1PackagistPackagist

58%

Total Score

caution

Usable with caveats: no registry release since 2017 and no recent commit activity.

Health Score Breakdown

Release historycaution

The package has existed for about 12 years and has seven releases, but its latest registry release was about 9 years ago with none in the last 12 months. That long release gap materially raises maintenance and compatibility concerns.

Repo commit activitycaution

The repository had no commits and no active maintainers in the last 3 months, consistent with a project that is currently dormant. This reinforces the concern raised by the old latest release.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem. No security scanning tool is present, but this is a hygiene limitation rather than evidence of abandonment on its own.

Security policycaution

The repository has no published security policy, leaving reporting and response expectations unclear. The organizational backing partly offsets the transparency gap but does not remove it.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Adrian Palmer
Ruben de Vries

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version >=6.0 <7.0.0
—
—
99designs/http-signatures
Version >=3.0.0 <5.0.0
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform