This is a mature, stable, and well-supported package with a release history dating to 2012, 41 releases, a current stable major version, an active non-archived organization-owned repository, and three active contributors with an even commit distribution in the last three months. The package is transparent and properly licensed, includes a substantial README and changelog, and its repository contains tests and CI tooling even though tests are not included in the artifact. Maintenance appears somewhat measured rather than highly active, with only one release in the last 12 months and three commits in the last three months; the absence of a security policy, security scanning, and explicit workflow token permissions are additional hygiene gaps. These concerns warrant modest caution but do not outweigh the strong maturity, backing, repository alignment, and maintenance evidence.
88%
Total Score
90
100
94
80
Three commits from three active maintainers in the last three months show ongoing maintenance, though the low volume supports a measured-maintenance caution rather than a highly active profile.
Composer build tooling is present, but no security scanning tools were detected; the missing scanning is a repository hygiene gap, not evidence of abandonment.
No repository security policy was found, which reduces transparency for vulnerability reporting and response expectations.
The one workflow does not declare top-level token permissions; although no write permissions were observed, explicit least-privilege configuration is absent.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-375681 react/http is vulnerable to Denial of Service (DoS) in versions 1.0.0 - 1.11.0. | 1.0.0 - 1.11.0 | High |
AIKIDO-2026-279795 react/http is vulnerable to Denial of Service (DoS) in versions 0.6.0 - 1.11.0. | 0.6.0 - 1.11.0 | High |
CVE-2023-26044 react/http is vulnerable to Uncontrolled Resource Consumption in versions 0.8.0 - 1.9.0. | 0.8.0 - 1.9.0 | Medium |
CVE-2022-36032 react/http is vulnerable to Improper Input Validation in versions 0.7.0 - 1.7.0. | 0.7.0 - 1.7.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.16 | — | — |
react/stream Version ^1.4 | — | — |
react/promise Version ^3.2 || ^2.3 || ^1.2.1 | — | — |
psr/http-message Version ^1.0 | — | — |
react/event-loop Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.