🔠Measure HTTP requests going through an react/http
66%
Total Score
75
93
50
The package defines post-install and post-update Composer scripts, which add install-time execution surface. The signal does not show that these scripts are harmful, so this is a limited supply-chain hygiene concern.
The package has made 7 releases over about 6 years, but none in the last 12 months and the median interval is about 270 days. Recent repository pull requests provide some compensating activity, but the release cadence remains slow.
The repository records zero commits and zero active maintainers in the last 3 months. Pull-request activity offers some evidence of ongoing maintenance, but direct commit activity is currently thin.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself show that the package is unsafe.
Both analyzed workflows grant top-level write permissions and all 2 action references are unpinned, weakening build reproducibility and limiting token scope. No untrusted checkout, script injection, or auditor findings were reported, which keeps this at caution rather than danger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^3.2 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
wyrihaximus/metrics Version ^2.1 | — | — |
thecodingmachine/safe Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.