Tests, extensive documentation, and release notes provide useful support for consumers. The project is less than a day old, and all 13 recent commits came from one contributor, so long-term maintenance remains uncertain.
62%
Total Score
83
100
88
67
The package is less than 1 day old despite 9 releases, so there is not yet enough history to establish durable maintenance or release stability.
One contributor made 100% of the 13 recent commits. Organization backing provides some handoff capacity, but no second active contributor is evidenced yet.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a security-sensitive HTTP library.
The only workflow was fully analyzed with no dangerous triggers or audit findings, but all 7 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phunkie/effect Version ^1.4 | — | — |
phunkie/phunkie Version ^1.5 | — | — |
phunkie/streams Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.