Usable with caveats: the package is licensed, documented, tested in its repository, and not deprecated or archived. However, version 2.0.0 has had no registry release for over six years and the repository shows no commits in the last three months, so maintenance appears limited.
58%
Total Score
50
86
63
The package declares post-install and post-update Composer lifecycle scripts, which add installation-time behavior that consumers should review. The signal does not show that these scripts are dangerous, so this is a limited caution rather than a severe risk.
The package has only two releases, with the latest published over six years ago and no releases in the last 12 months. This is a meaningful maintenance concern for a dependency, although the repository remains available and unarchived.
The repository recorded zero commits and zero active maintainers in the last three months, indicating little recent development activity. This is partly offset by the repository not being archived and by its existing maintenance tooling.
The repository has one star, one fork, and one watcher, providing little external evidence of broad adoption. Popularity is supporting evidence only, so this modestly reinforces the maintenance concern rather than deciding it.
The repository has no security policy, leaving vulnerability-reporting guidance undocumented. This is a transparency gap, but it is not by itself evidence that the package is unfit to use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^1 | — | — |
psr/http-message Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.