Usable with caveats: the package is actively releasing and has a matching organization-backed repository with tests. It is only 20 days old, all recent commits come from one contributor, and security-policy coverage is limited.
72%
Total Score
90
100
89
90
The package is only 20 days old but has already produced 8 releases, with a median interval of about 2 days. This shows strong early activity, though it does not yet demonstrate long-term maintenance.
One contributor made all 8 recent commits, creating concentration risk. Because the repository is owned by an organization, maintenance can potentially be handed off, so this is a caution rather than a severe risk.
Composer build tooling is present, but no security-scanning tool is detected. This is a transparency and hygiene gap, though the repository is small and has explicit static-analysis configuration files.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a genuine transparency gap for a network-facing HTTP client.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/http-client Version ^5.3.6 | — | — |
revolt/event-loop Version ^1.0.9 | — | — |
symfony/http-client Version ^8.1.4 | — | — |
symfony/http-client-contracts Version ^3.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.