Sign and verify HTTP messages with Guzzle 6
58%
Total Score
caution
Usable with caveats: no registry release since 2017 and no recent commit activity.
The package has existed for about 12 years and has seven releases, but its latest registry release was about 9 years ago with none in the last 12 months. That long release gap materially raises maintenance and compatibility concerns.
The repository had no commits and no active maintainers in the last 3 months, consistent with a project that is currently dormant. This reinforces the concern raised by the old latest release.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tool is present, but this is a hygiene limitation rather than evidence of abandonment on its own.
The repository has no published security policy, leaving reporting and response expectations unclear. The organizational backing partly offsets the transparency gap but does not remove it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version >=6.0 <7.0.0 | — | — |
99designs/http-signatures Version >=3.0.0 <5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.