Clear documentation, tests, licensing, and read-only workflow permissions make the package easy to evaluate. Its single release and lack of observed commit history leave maintenance longevity unproven; workflow actions are also unpinned.
68%
Total Score
50
100
88
67
One registry maintainer is listed, which creates a narrow publishing base. The repository is also owned by the same individual, so there is no organizational backing shown to offset that concentration.
The package has only one release and was published today, so there is no release history to demonstrate sustained maintenance. This is an important uncertainty for a new dependency, not evidence of abandonment by itself.
The repository has no commits or active maintainers observed in the last three months. Because the project was created today, this is mainly an unproven maintenance record rather than confirmed abandonment.
Composer build tooling is present, but no security-scanning tool is reported. That is a modest transparency and hygiene gap, not a severe dependency risk on its own.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency somewhat for a library intended for application integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
znojil/http Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.