Usable with caveats: it is a small, clearly documented MIT package with repository tests and no install-time scripts, but the only registry release was in 2017 and there have been no commits in the last three months. Review compatibility and repository activity before adopting it as a new dependency.
58%
Total Score
67
100
81
90
This is the package's only release, published about 8 years ago, with no releases in the last 12 months. That makes current compatibility and maintenance intent difficult to establish.
The repository recorded zero commits and zero active maintainers in the last three months. Although the recent push indicates some repository activity, the measured commit inactivity is a maintenance concern.
There are no open issues and three open pull requests, but none were merged or newly active in the last month. The absence of issues is positive, while the unmerged pull requests provide a small sign of unresolved maintenance work.
The repository has only 2 stars, 1 fork, and 1 watcher, indicating limited adoption and a small external support community. Low popularity is supporting evidence rather than a decisive health problem for a narrowly scoped middleware package.
The repository uses Make and Composer for builds, showing basic project tooling, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^0.8.0 | — | — |
react/promise Version ^2.5 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.