Package Health

simsoft/http-client

This release appears healthy and reasonably safe to depend on: it has a stable major version, frequent recent releases, an active and non-archived repository, current commit and pull-request activity, a matching repository with clear package references, a permissive MIT license, documented security reporting, and restrictive workflow permissions. The main limitations are the very small visible maintainer and contributor base, zero repository popularity, and the absence of automated security-scanning tooling; these create some continuity and assurance concerns but are partly offset by two active contributors, 32 commits in the last 3 months, 21 merged pull requests in the last month, and substantial repository documentation and tests.

Latest 5.0.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which creates a publishing continuity concern for an independently owned project. Repository activity from two contributors provides some compensation, but does not eliminate the single-publisher risk.

Project backingcaution

The repository is owned by the sim-soft user account rather than an organization, so there is no organizational maintenance cushion to offset the small maintainer base. Active repository and release signals nevertheless show current individual backing.

Repo popularitycaution

The repository has zero stars, forks, and watchers, which limits community validation and external adoption evidence. Popularity is supporting evidence rather than decisive, and the active release and commit signals compensate for much of this gap.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanning layer is a genuine assurance gap, although the repository does provide a security policy and controlled CI permissions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

V. Zang, Loo

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
psr/http-message
Version ^1.1|^2.0

Weekly Downloads

Info

Last Published
15 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform