Usable with caveats: the package is actively published, current, licensed, and backed by a matching organization repository. The main concerns are one-person commit activity, no repository tests or security policy, and very limited adoption evidence.
72%
Total Score
100
100
83
90
The artifact includes a README, which is useful for this small library, but it is only 88 characters and the repository reports no tests or changelog. The absent tests reduce confidence in maintenance quality, while missing tests and changelog in the published artifact are normal.
The repository has 4 stars, 0 forks, and 1 watcher, so independent adoption evidence is limited. Low popularity is supporting caution rather than a verdict because the package is small and shows recent activity.
Composer is used as the build tool, but no security scanning tools are reported. Standard build tooling is appropriate, while the missing scanning is a modest transparency gap.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified. For a package handling HTTP requests and responses, this is a genuine but not severe transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
evas-php/evas-base Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.