This release is usable but still immature: it is only 11 days old, remains on the 0.x version line, and all recent repository commits come from one contributor. Those risks are partly offset by an active, non-archived organization-backed repository, three releases in the first 11 days, successful issue/PR throughput, repository tests that compensate for tests not being packaged, clear Apache-2.0 licensing, and conservative CI permissions with no dangerous workflow patterns. The absence of security scanning and a security policy, zero repository popularity, and limited release history warrant caution before adopting it as a critical dependency.
68%
Total Score
75
100
78
90
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.