The package includes a substantial README, repository tests, release notes, and matching MIT licensing. Workflow references are not pinned and the repository recorded no commits from any maintainer in the last three months, so ongoing maintenance and build reproducibility deserve attention.
69%
Total Score
75
100
50
The repository recorded zero commits and zero active maintainers during the last three months. A release was published around six months ago, but the lack of subsequent development is a maintenance caution.
The repository has no published security policy. That is a transparency gap for a library handling HTTP messages, although repository security scanning is present.
The audit analyzed the single workflow completely and found no dangerous triggers, untrusted checkouts, or injection issues. However, all 11 action references are unpinned, leaving build automation more exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.