Clear documentation, repository tests, release notes, and organizational backing improve confidence. The latest release was in June 2025, with no commits in the past three months, while two workflow actions remain unpinned.
62%
Total Score
75
88
75
The project has existed since May 2015 with 28 releases, but it has made no release in the past 12 months; the latest release was in June 2025. This weakens current-maintenance confidence despite a long release history.
There were zero commits and zero active maintainers in the past three months. Combined with no registry release in the past year, this is a meaningful sign of slowed maintenance.
The repository uses Composer, but no security-scanning tools were detected. This is a modest transparency and maintenance-hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. For an HTTP client library, that leaves vulnerability-reporting expectations less clear and modestly lowers transparency.
The only workflow was fully analyzed, uses read-only permissions, and has no detected high-confidence findings or untrusted execution paths. However, both action references are unpinned, leaving avoidable build-reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/psr7 Version ^1.6 | — | — |
psr/http-message Version ^1.0 | — | — |
vanilla/garden-utils Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.