The project has a very small footprint and no security policy or scanning. Its stable version and clean install metadata do not offset the long maintenance gap.
42%
Total Score
0
72
67
The package has made four releases since May 2023, but none in the last 12 months and the latest release was over three years ago. The short earlier release interval does not compensate for the prolonged inactivity.
The repository recorded no commits and no active maintainers in the last three months, consistent with the latest push being over three years ago. This is a strong abandonment concern for a package developers may need maintained dependencies from.
Neither the package metadata nor the repository contains a license. That creates a real adoption and redistribution risk, even though the package is small.
The package and repository each contain only four files: a README, app.php, composer.json, and .gitignore. This may fit a minimal example project, but it provides little evidence of mature library engineering.
The repository has two stars, no forks, and one watcher. Popularity is not required for a healthy small package, but these very low adoption signals provide little supporting evidence of ongoing use.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^1.9 | — | — |
clue/socks-react Version ^1.4 | — | — |
clue/http-proxy-react Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.