Package Health

ext/http

The repository has a security policy and no install-time scripts. Resolve the licensing mismatch before adoption; the placeholder documentation and limited maintenance activity suggest weak ongoing support.

Latest 1.0.3PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Licensedanger

The manifest declares MIT, but the artifact license file is detected as GPL-2.0. Although a license file is present, the mismatch creates material uncertainty about the terms developers may receive.

Package scaffoldingcaution

The package includes a README, and the repository has tests, but the published README is only 464 characters and remains an unfilled template with placeholder installation and usage content. That weakens consumer transparency for a library.

Release historycaution

All four releases occurred within roughly six hours on October 30, 2025, followed by no later release despite the package being about 11 months old. This suggests an initial burst rather than an established release cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. With no newer release activity to compensate, this is evidence of limited ongoing maintenance.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance-process gap, not evidence of malicious behavior.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Cloudflying

Direct Dependencies

DependencyLast ReleaseScore
ext/support
Version ^1.0
ext/exception
Version ^1.0.3
psr/http-message
Version ^2.0
guzzlehttp/guzzle
Version ^7.10
composer/ca-bundle
Version ^1.5

Weekly Downloads

Info

Last Published
10 months ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform