The package has a minimal README, no tests, and no security policy. Its declared MIT license and matching repository provide basic transparency, but the long maintenance gap makes future fixes and compatibility uncertain.
37%
Total Score
0
71
50
The package is over 5 years old with six releases but none in the last 12 months; its last registry release was in October 2020, indicating severe abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the unchanged registry history and leaving maintenance capacity uncertain.
The package includes a README, but it is only 19 characters long and provides little integration guidance; the absence of tests is normal packaging practice and is not treated as a gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported for a network-facing proxy package.
The assessed version is still a prerelease, and all recent releases are prereleases, so the package has not demonstrated a stable release track.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^0.8.6 | — | — |
clue/buzz-react Version ^2.8 | — | — |
react/event-loop Version ^1.1 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
react/http-client Version ^0.5.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.