Async HTTP client with connection pooling, HTTP/2 multiplexing, middleware, and composable decorators for redirects and retries
38%
Total Score
unhealthy
Risky: artifact is nearly identical to a much more established package, making this release easy to confuse with the intended dependency.
The artifact overlap is 0.9787 with php-standard-library/php-standard-library, which has 376,811 monthly downloads versus 7 and 73 stable releases versus 3. Although the package does not explicitly borrow the lookalike's identity, the near-identical artifact makes this a severe adoption risk.
All recent commit activity is concentrated in one contributor. Organization backing provides some handoff capacity, but no second active contributor is shown to compensate for the concentration.
The repository had only 1 commit and 1 active maintainer in the last 3 months, indicating very limited recent maintenance activity for a complex HTTP client.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of unsafe behavior.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a network-facing client.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-standard-library/h2 Version ^6.2 | — | — |
php-standard-library/io Version ^6.2 | — | — |
php-standard-library/ip Version ^6.0 | — | — |
php-standard-library/tcp Version ^6.2 | — | — |
php-standard-library/tls Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.