Tests, a stable release, and no install-time scripts reduce immediate adoption friction. The repository/package-name mismatch makes provenance less clear, so this old release is difficult to justify for a new dependency.
40%
Total Score
67
75
The package has had only two releases, both in August 2017, with no release in roughly nine years. That strongly indicates abandonment risk despite the stable 1.0.1 version.
The repository name does not match the package name, and no README mention was available. This weakens confidence that the linked source repository is specifically for this package.
The linked repository is not archived, which is a positive sign, but its last push was also in August 2017 and therefore does not demonstrate current maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. This is a transparency gap, though not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
logics/http Version 0.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.