Package Health

bohan/promise-http-client

The package includes an MIT license, a README, tests, release notes, and no install-time scripts. Its small release history and lack of security scanning provide little reassurance beyond the decisive maintenance concerns.

Latest v0.4.0PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names manyou/promise-http-client as its replacement. This is a direct warning against taking a new dependency on this release.

Release historydanger

The package has only four releases, no releases in the last 12 months, and its latest release was March 15, 2021. The long period without a new release reinforces the abandonment concern.

Repository archiveddanger

The linked repository is archived, with its last push on November 8, 2022, indicating the source is no longer actively maintained. This materially increases abandonment and maintenance risk.

Project backingcaution

The repository is owned by a user account rather than an organization, so the single registry maintainer is consistent with the available project backing. This offers limited continuity protection.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are reported. That is a modest transparency gap, though it does not outweigh the maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Bohan Yang

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1
—
—
guzzlehttp/promises
Version ^1.4
—
—
symfony/http-client-contracts
Version ^1.0 || ^2.0
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform