Documentation and maintenance support are limited. The package is licensed and not deprecated, but its two-year-old release and inactive repository make long-term support uncertain.
55%
Total Score
50
100
81
75
The published library has no README, tests, or changelog, while the repository also reports no tests or changelog. Missing tests and changelog are normal for published artifacts, but the absent README reduces consumer transparency for a library.
The repository owner is a user account rather than an organization, and the registry has one maintainer. This provides limited visible backing, but registry access records alone do not establish maintenance capacity.
Only two releases exist, with the latest published about two years ago and no releases in the last 12 months. This is a meaningful maintenance concern for a dependency, despite the moderate 46-day interval between the initial releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This weakens evidence of ongoing maintenance.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
verdient/http-api Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.