Package Health

drift/http-kernel

The package includes tests, release notes, a matching repository, and an MIT license. Its small audience and lack of security policy leave less independent assurance for a library that is no longer actively maintained.

Latest 0.1.20PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has 21 releases over roughly four years, but none in the last 12 months and its latest release was on August 28, 2023. This indicates a prolonged maintenance gap.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this is evidence of stalled maintenance.

Repo issue activitycaution

There were three open issues and no issue or pull-request activity in the last month. This is consistent with limited current project attention, though the small backlog is not severe on its own.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. For a library, that reduces automated assurance and is a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy. This leaves vulnerability reporting and response expectations unclear, which matters for a reusable HTTP framework component.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marc Morera

Direct Dependencies

DependencyLast ReleaseScore
react/http
Version ^1.0
react/promise
Version ^3
symfony/routing
Version ^5.0
clue/block-react
Version ^1.3
symfony/filesystem
Version ^5.0

Weekly Downloads

Info

Last Published
3 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform