Package Health

vanilla/garden-http

Clear documentation, repository tests, release notes, and organizational backing improve confidence. The latest release was in June 2025, with no commits in the past three months, while two workflow actions remain unpinned.

Latest v3.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The project has existed since May 2015 with 28 releases, but it has made no release in the past 12 months; the latest release was in June 2025. This weakens current-maintenance confidence despite a long release history.

Repo commit activitycaution

There were zero commits and zero active maintainers in the past three months. Combined with no registry release in the past year, this is a meaningful sign of slowed maintenance.

Repo toolingcaution

The repository uses Composer, but no security-scanning tools were detected. This is a modest transparency and maintenance-hygiene gap, not evidence that the package is unsafe.

Security policycaution

The repository has no security policy. For an HTTP client library, that leaves vulnerability-reporting expectations less clear and modestly lowers transparency.

Workflow auditcaution

The only workflow was fully analyzed, uses read-only permissions, and has no detected high-confidence findings or untrusted execution paths. However, both action references are unpinned, leaving avoidable build-reproducibility risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Todd Burry

Direct Dependencies

DependencyLast ReleaseScore
slim/psr7
Version ^1.6
—
—
psr/http-message
Version ^1.0
—
—
vanilla/garden-utils
Version ^1.1
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform