The package is stable and includes a README, tests, and release notes, but its maintenance picture is thin. The repository has no security policy or scanning tools, leaving limited evidence of ongoing oversight.
44%
Total Score
0
100
72
75
The package has only one registry release, published in January 2022, with no releases in the following four years. This is strong evidence of abandonment risk for a library dependency.
The repository recorded zero commits and zero active maintainers during the last three months of the assessment period, consistent with the long release gap. No provided signal shows recent maintenance to offset this.
The repository name matches the package, supporting that it is the intended source, but the README does not mention the package name. This creates a small transparency concern without proving the repository is unrelated.
The repository has one star, one fork, and one watcher, indicating a very small user and contributor footprint. Popularity is supporting evidence only, but it provides little compensating confidence for the maintenance gap.
Composer build tooling is present, showing a defined packaging path. However, the absence of security scanning tools leaves a modest oversight gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.