Package Health

amphp/http

Repository activity has slowed, with no commits or merged pull requests in the last three months. The organization backing, tested source tree, security policy, and documented release notes provide useful maintenance and transparency support.

Latest v2.1.2PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Release historycaution

The package has 23 releases over roughly 8 years, but none in the last 12 months and its latest release was in November 2024, indicating a meaningful maintenance slowdown.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, a direct warning that ongoing maintenance capacity may be limited.

Repo issue activitycaution

Only one issue and two pull requests are open, but there were no new or closed issues and no new or merged pull requests in the last month, consistent with limited current activity.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. All four action references are unpinned, which is a supply-chain hygiene weakness, but no dangerous trigger or token permission pattern is present.

Vulnerabilities

TitleVersionsSeverity
CVE-2024-2653
amphp/http is vulnerable to Security Vulnerability in versions 2.0.0 - 2.1.0 and 0.0.0 - 1.7.2.
0.0.0 - 1.7.22.0.0 - 2.1.0
High

Package versions

Maintainers

Niklas Keller
Aaron Piotrowski

Direct Dependencies

DependencyLast ReleaseScore
amphp/hpack
Version ^3
amphp/parser
Version ^1.1
psr/http-message
Version ^1 | ^2
league/uri-components
Version ^2.4.2 | ^7.1

Weekly Downloads

Info

Last Published
1 year ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform