Repository activity has slowed, with no commits or merged pull requests in the last three months. The organization backing, tested source tree, security policy, and documented release notes provide useful maintenance and transparency support.
65%
Total Score
67
100
94
100
The package has 23 releases over roughly 8 years, but none in the last 12 months and its latest release was in November 2024, indicating a meaningful maintenance slowdown.
The repository recorded zero commits and zero active maintainers in the last three months, a direct warning that ongoing maintenance capacity may be limited.
Only one issue and two pull requests are open, but there were no new or closed issues and no new or merged pull requests in the last month, consistent with limited current activity.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. All four action references are unpinned, which is a supply-chain hygiene weakness, but no dangerous trigger or token permission pattern is present.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-2653 amphp/http is vulnerable to Security Vulnerability in versions 2.0.0 - 2.1.0 and 0.0.0 - 1.7.2. | 0.0.0 - 1.7.22.0.0 - 2.1.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
amphp/hpack Version ^3 | — | — |
amphp/parser Version ^1.1 | — | — |
psr/http-message Version ^1 | ^2 | — | — |
league/uri-components Version ^2.4.2 | ^7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.