52%
Total Score
caution
Usable with caveats: no releases or commits since June 2022.
Only one account has registry publishing access. That is a thin maintainer base for continuity, though the linked repository and package identity match.
The repository is owned by an individual account rather than an organization, so there is no provided organizational backing to compensate for the thin maintainer base.
The package has had no release in more than four years, with all five releases clustered on June 27, 2022. That strongly lowers confidence in ongoing maintenance, although the repository is not archived.
There were no commits and no active maintainers in the last three months, consistent with the long release gap. This is a meaningful abandonment concern rather than a cosmetic gap.
The repository has one star, one fork, and no watchers, providing little evidence of a broad user or contributor base. Popularity is supporting evidence, so this reinforces—but does not independently determine—the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pear/http_request2 Version ~2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.