Package Health

tyhpdef/php-http-message

It has a matching repository, an Apache-2.0 license, Composer tooling, and organization ownership. The tiny metapackage has no security policy, so long-term maintenance remains unproven.

Latest 1.16.2PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historycaution

This is the package's first release, published 0 days ago, so there is no observed release cadence or track record yet. Its organization-backed repository provides some context, but not evidence of sustained maintenance.

Repo commit activitycaution

There were no commits or active maintainers in the past 3 months, but the repository and package were created on the same day. This leaves maintenance capacity unproven rather than demonstrating a collapse in activity.

Repo toolingcaution

The repository uses Composer build tooling, which fits the package ecosystem. No security scanning tool was detected, a modest hygiene gap for a very small repository.

Security policycaution

The linked repository has no security policy. That reduces disclosure transparency, although the package is a small metapackage with no install-time scripts.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tyhpdef/php-http-message-impl
Version ~1.16.2.0
—
—

Weekly Downloads

Info

Last Published
6 hours ago
Created
6 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform