The repository was updated in November 2021, but there has been no recent commit activity or security scanning. Clear licensing, matching source, and no install-time scripts reduce adoption friction.
58%
Total Score
75
100
79
67
This package has only one release, published over 11 years ago, with no releases in the last 12 months. That is a substantial maintenance concern, although the repository was pushed more recently.
There were no commits and no active maintainers in the last three months. Combined with the old sole release, this indicates a meaningful abandonment risk.
The repository uses Composer, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not evidence of a security problem.
No security policy is present in the repository. For an old, externally downloading utility, this reduces transparency around reporting and maintenance expectations.
Version 0.0.1 is not marked as a prerelease, but its pre-1.0 version signals an immature release line with no later stable evolution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spindle/httpclient Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.