The codebase is clearly identified and easy to inspect, with MIT licensing and no install-time scripts. Its six runtime dependencies and absent security policy add modest review burden.
61%
Total Score
50
86
83
The package has five releases since October 2019, but none in the last 12 months; its latest release was about 15 months ago. This indicates a small, quiet project rather than an abandoned one by itself.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance concern, though it is tempered by the release roughly 15 months ago.
The repository has one star and two forks, showing limited adoption and little community support. Popularity is supporting evidence only, so this modestly increases maintenance uncertainty rather than deciding the verdict.
The repository has no security policy, leaving vulnerability-reporting and response expectations unclear. This is a transparency gap, but not a severe dependency risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-http/httplug Version ^2.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
php-http/discovery Version ^1.7 | — | — |
php-http/cache-plugin Version ^2.0 | — | — |
php-http/client-common Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.