Package Health

gipfl/curl

The package has a clear MIT license, a matching repository, and no install-time scripts. Its maintenance and security transparency are limited, so pinning this version is preferable to relying on ongoing updates.

Latest v0.5.0PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historycaution

The package has seven releases since November 2021, but none in the last 12 months; the latest release was about one year ago. This points to slowing maintenance rather than abandonment by itself.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance warning, although the repository was updated when this version was released.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This modestly reduces automated assurance without showing an immediate dependency risk.

Security policycaution

The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a network-facing HTTP library.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Thomas Gelf

Direct Dependencies

DependencyLast ReleaseScore
react/stream
Version >=1.0
react/promise
Version >=2
guzzlehttp/psr7
Version >=1.6
psr/http-message
Version ^1.0
react/event-loop
Version >=1.0

Weekly Downloads

Info

Last Published
1 year ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform