Its small scope and simple dependency set make the codebase easy to inspect. The repository has no automated security scanning or security policy, so ongoing upkeep and vulnerability handling are limited.
43%
Total Score
33
100
72
83
The package has only two releases, with the latest published on November 29, 2021 and none in the past 12 months. This is strong evidence of abandonment for a library still expected to track its ecosystem.
There were zero commits and zero active maintainers in the past three months, consistent with the last push occurring in November 2021. This materially raises abandonment risk.
One registry account has publish access. That is a thin publishing base for an independently owned project and increases continuity risk when activity has already stopped.
There are no open issues or pull requests and no activity in the past month. The clean tracker is not inherently positive because it may reflect an inactive project rather than resolved maintenance.
The repository has 2 stars, 0 forks, and 1 watcher. Low adoption is supporting evidence of limited external validation, but it is not decisive for a small, focused client.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version 4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.