Package Health

mulertech/http-request

The package includes a clear license, tests, a README, and release notes for this version. Workflow references are unpinned and the repository has no security policy or scanning, adding maintenance and supply-chain hygiene concerns.

Latest v1.0.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

Only two releases exist, with no release in the last 12 months; the latest registry release was about 1 year 11 months ago. Recent repository commits partly offset the stale registry cadence, but do not remove the adoption risk.

Repo bus factorcaution

The repository had one contributor responsible for all two commits in the last three months, leaving maintenance concentrated in a single person. The active commits are positive, but there is no demonstrated contributor redundancy.

Security policycaution

No repository security policy or security scanning tool was detected, reducing transparency around vulnerability reporting and automated checks. The package's tests and active recent commits provide some compensating project evidence.

Workflow auditcaution

All 18 analyzed action references are unpinned and one workflow grants top-level write permissions, which weakens build reproducibility and token minimization. No untrusted checkout, script injection, dangerous trigger, or auditor finding was reported, so this is a hygiene caution rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sébastien Muler

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^2
psr/http-message
Version ^2
mulertech/char-manipulation
Version ^1
mulertech/array-manipulation
Version ^2

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform