Package Health

react/http

This is a mature, stable, and well-supported package with a release history dating to 2012, 41 releases, a current stable major version, an active non-archived organization-owned repository, and three active contributors with an even commit distribution in the last three months. The package is transparent and properly licensed, includes a substantial README and changelog, and its repository contains tests and CI tooling even though tests are not included in the artifact. Maintenance appears somewhat measured rather than highly active, with only one release in the last 12 months and three commits in the last three months; the absence of a security policy, security scanning, and explicit workflow token permissions are additional hygiene gaps. These concerns warrant modest caution but do not outweigh the strong maturity, backing, repository alignment, and maintenance evidence.

Latest v1.11.1PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Repo commit activitycaution

Three commits from three active maintainers in the last three months show ongoing maintenance, though the low volume supports a measured-maintenance caution rather than a highly active profile.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected; the missing scanning is a repository hygiene gap, not evidence of abandonment.

Security policycaution

No repository security policy was found, which reduces transparency for vulnerability reporting and response expectations.

Token permissionscaution

The one workflow does not declare top-level token permissions; although no write permissions were observed, explicit least-privilege configuration is absent.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-375681
react/http is vulnerable to Denial of Service (DoS) in versions 1.0.0 - 1.11.0.
1.0.0 - 1.11.0
High
AIKIDO-2026-279795
react/http is vulnerable to Denial of Service (DoS) in versions 0.6.0 - 1.11.0.
0.6.0 - 1.11.0
High
CVE-2023-26044
react/http is vulnerable to Uncontrolled Resource Consumption in versions 0.8.0 - 1.9.0.
0.8.0 - 1.9.0
Medium
CVE-2022-36032
react/http is vulnerable to Improper Input Validation in versions 0.7.0 - 1.7.0.
0.7.0 - 1.7.0
Medium

Package versions

Maintainers

Christian Lück
Cees-Jan Kiewiet
Jan Sorgalla
Chris Boden

Direct Dependencies

DependencyLast ReleaseScore
react/socket
Version ^1.16
—
—
react/stream
Version ^1.4
—
—
react/promise
Version ^3.2 || ^2.3 || ^1.2.1
—
—
psr/http-message
Version ^1.0
—
—
react/event-loop
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
23 days ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform