Package Health

coisa/http-client

The stable version, MIT license, repository tests, and build and security tooling support adoption. Unpinned workflow actions and one registry maintainer add maintenance and release-process concerns. Pin this version only if its unchanged feature set meets your needs.

Latest 1.2.2PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The package has had no release in over four years and no releases in the last 12 months, which is a meaningful maintenance concern despite six early releases over a short interval.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months. This is strong evidence of currently inactive development and reinforces the stale release history.

Maintainerscaution

Only one account has registry publishing access. That is a limited publishing base for a user-owned project and increases continuity risk when combined with no recent commit activity.

Project backingcaution

The registry namespace and repository are owned by the same individual account, so there is no organization backing shown to compensate for the single-maintainer model.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, with one pull request still open, suggesting limited recent project activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Felipe Sayão Lobato Abreu

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/http-message
Version ^1.0
—
—
coisa/http-factory
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform