The package includes its license, README, repository tests, changelog, and a small runtime dependency set. However, it has had no release or repository commit activity for about five years, while its workflows use unpinned images and actions.
42%
Total Score
0
100
86
75
The latest release was about five years ago, and there have been no releases in the last 12 months. The package has 128 historical releases, but that does not offset the prolonged current inactivity.
There were zero commits and zero active maintainers in the last three months. Combined with the old last push, this is strong evidence that maintenance has stopped.
The repository has no published security policy. That reduces transparency for reporting and handling vulnerabilities in a network-facing HTTP client.
All 20 action references are unpinned, and the audit found two high-confidence unpinned container-image findings. No untrusted checkout or script-injection paths were detected, limiting this to a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
guzzlehttp/promises Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.