The MIT license, clear README, small dependency set, and matching organization-owned repository provide useful transparency. Pin v1.2.4 and plan for maintenance alternatives because development has been inactive since December 2022.
55%
Total Score
50
100
72
67
The package has seven releases, but none in the last 12 months; its latest release was in December 2022, indicating prolonged maintenance inactivity.
There were no commits or active maintainers in the last three months, reinforcing the release-history evidence that maintenance has stopped.
The repository has only 4 stars and no forks, offering little external adoption evidence; this is supporting context rather than a standalone health verdict.
Composer is used for the build, but no security scanning tools are configured. That is a hygiene gap, though it is less significant than the maintenance inactivity.
The repository is not archived, but its last push was in December 2022, so the non-archived status does not offset the evidence of inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3|^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.