It has a small, coherent package with tests, documentation, and an MIT license. The organization-backed repository is not archived, but the lack of security tooling leaves maintenance assurance thinner; pin 2.0.1.
67%
Total Score
75
100
86
50
The package has existed since 2017 and has seven releases, but it has had no release in the last 12 months, which lowers confidence in active maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. The recent 2.0.1 release provides some evidence of maintenance, but current activity is absent.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and assurance gap for a dependency.
The repository has no published security policy, leaving vulnerability reporting and response expectations unspecified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^1.0 | — | — |
ratchet/rfc6455 Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.