The project has clear documentation, tests in the repository, and an MIT license. Its single published release and lack of recent commits leave maintenance and compatibility uncertain, while workflow pinning is weak.
40%
Total Score
50
100
80
67
This is the only release, published about 2 years and 10 months ago, with no releases in the last 12 months. That leaves compatibility and maintenance uncertain for a library dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since its only release. No provided activity signal compensates for this maintenance risk.
The repository has no security policy. For a library that handles HTTP requests, this reduces the project's vulnerability-reporting transparency, although it does not by itself show abandonment.
All 12 analyzed action references are unpinned, and a high-confidence audit found an unpinned container image in cs-fixes.yml. The workflows have no untrusted checkouts or script injection, so this is a hygiene and supply-chain weakness rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.