The package includes tests, release notes, a matching repository, and an MIT license. Its small audience and lack of security policy leave less independent assurance for a library that is no longer actively maintained.
58%
Total Score
67
88
50
The package has 21 releases over roughly four years, but none in the last 12 months and its latest release was on August 28, 2023. This indicates a prolonged maintenance gap.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this is evidence of stalled maintenance.
There were three open issues and no issue or pull-request activity in the last month. This is consistent with limited current project attention, though the small backlog is not severe on its own.
Composer build tooling is present, but no security scanning tools were detected. For a library, that reduces automated assurance and is a modest transparency and maintenance gap.
The repository has no security policy. This leaves vulnerability reporting and response expectations unclear, which matters for a reusable HTTP framework component.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^1.0 | — | — |
react/promise Version ^3 | — | — |
symfony/routing Version ^5.0 | — | — |
clue/block-react Version ^1.3 | — | — |
symfony/filesystem Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.