Package Health

guzzlehttp/psr7

Healthy and suitable to depend on. It has a long, active release history, current repository activity, clear licensing, tests and release notes, and organization backing; maintenance is currently concentrated in one contributor, but the project remains actively maintained and well structured.

Latest 3.1.0PackagistPackagist

92%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made all 91 commits in the last three months, giving the project a concentrated current bus factor. This is a caution, but organization backing and the strong release and repository activity reduce the abandonment concern.

Repo toolingcaution

The repository uses Make and Composer, but no security scanning tools were detected. The missing automated scanning is a modest transparency gap rather than a severe health concern because the repository has other established build and security practices.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-59882
guzzlehttp/psr7 is vulnerable to Improper Input Validation in versions 0.0.0 - 2.12.3.
0.0.0 - 2.12.3
Medium
CVE-2026-55766
guzzlehttp/psr7 is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 0.0.0 - 2.12.1.
0.0.0 - 2.12.1
Medium
AIKIDO-2026-11089 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
guzzlehttp/psr7 is vulnerable to Denial of Service in versions 2.0.0 - 2.10.3.
2.0.0 - 2.10.3
Medium
AIKIDO-2026-10932
guzzlehttp/psr7 is vulnerable to Server-side Request Forgery (SSRF) in versions 0.0.1 - 2.10.1.
0.0.1 - 2.10.1
Medium
AIKIDO-2026-10931
guzzlehttp/psr7 is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 0.0.1 - 2.10.1.
0.0.1 - 2.10.1
Medium

Package versions

Maintainers

Graham Campbell
Michael Dowling
George Mponos
Tobias Nyholm
Márk Sági-Kazár
Tobias Schultze
Márk Sági-Kazár

Direct Dependencies

DependencyLast ReleaseScore
psr/http-factory
Version ^1.1
psr/http-message
Version ^2.0
symfony/polyfill-php80
Version ^1.25
symfony/polyfill-php82
Version ^1.27

Weekly Downloads

Info

Last Published
29 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform