It includes a substantial README, tests, a matching MIT license, and no install-time scripts. The single-user project has no security policy, and its very small public footprint provides little evidence of established support.
62%
Total Score
75
100
89
83
Only one registry account has publish access. That is not proof of poor maintenance, but it leaves limited visible publishing redundancy for a project without organizational backing.
This package was released only once and is less than a day old, so there is no release track record from which to judge sustained maintenance.
The repository shows zero commits and zero active maintainers in the last three months. Because the package is newly released, this may reflect its age, but it leaves maintenance capacity unproven.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap, not a severe risk on its own.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities in an HTTP client library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.