The package has a clear README, repository tests, recent releases, and no install-time scripts. Its license declarations disagree, and one maintainer handles all recent commits without a security policy.
68%
Total Score
50
83
75
The manifest declares ISC while the artifact and repository license files identify MIT. A license is present, but the mismatch creates avoidable legal and transparency uncertainty.
One contributor made all two recent commits, leaving maintenance highly concentrated. There is no organization backing signal to offset that concentration.
Two commits were made in the last three months, showing recent activity, but the volume is limited and does not establish broad maintenance capacity.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is not by itself evidence that the package is unsafe.
Version v0.2.3 is not a prerelease, but the package remains below 1.0. That signals an evolving API and warrants more caution than a mature stable-major release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
fig/http-message-util Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.