Its MIT license, minimal dependency set, and lack of install-time scripts keep adoption straightforward. The project has not changed since February 2018, while documentation and security practices are thin; use only if its narrow API is already sufficient.
42%
Total Score
100
60
75
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README is a documentation gap for a library consumers must integrate with.
The package has only 3 releases, with none in the last 12 months, and its latest release was in February 2018. This long period without a release materially raises abandonment risk.
The linked repository name does not match the package name, and no README mention was available. For a small standalone package, that weakens confidence that the repository clearly documents and backs this package.
The repository is not archived, which avoids a severe abandonment signal, but its last push was also in February 2018 and does not offset the stale release history.
The repository has no security policy. This is a transparency and maintenance gap, though the package's very small interface-only file tree limits the practical weight of the omission.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fig/http-message-util Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.