Usable with caveats: this is a very small, early-stage package with limited release history and no recent commit activity. The linked repository does not match the package name or mention it in its README, so verify that it is the intended source before adopting it.
58%
Total Score
50
100
75
83
Only two releases have been published since November 2022, with a median interval of about 1,154 days; one release in the last 12 months shows some activity but limited maturity.
The repository had zero commits and zero active maintainers in the last three months, indicating limited current maintenance capacity; the January 2026 push provides only partial compensation.
The repository name does not match the package name and its README does not mention this package, so the source relationship is unclear and should be verified before relying on it.
No security policy was found. This is a transparency gap for reporting vulnerabilities, although the package is small and no dangerous workflows were detected.
The current version is v0.1.1 rather than a stable major release, which indicates an early-stage API and greater compatibility risk for dependents.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
francerz/http Version ^0.4 | — | — |
psr/http-message Version ^1.0 | — | — |
fig/http-message-util Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.