I personally treat it as a supply chain risk, as there are no longer any way to report any bugs and security problems.
Switching to other libraries like requests and aiohttp and supporting them by contributing is clearly a better option.
When I say _considerable_, I'm essentially saying _nearly every_ big tech. The one I can tell for sure is OpenAI (not a fan of them though).
Remember xz attack?
Clearly, the maintainer doesn't want to do this job anymore, and it's not a requirement when releasing your code to also do stuff unrelated to programming.