Its MIT terms, documented setup, and small dependency footprint make adoption straightforward. The limited public footprint leaves little evidence of ongoing support, so pinning this version carries maintenance risk.
54%
Total Score
50
100
67
75
The package is nearly five years old, has six releases, and has had no release in the last 12 months. This is strong evidence of stalled maintenance for a library dependency.
There are no open issues or pull requests and no activity in the last month. This is consistent with an inactive project, though the lack of open work is not inherently negative.
Two stars, no forks, and one watcher indicate a very small public user and contributor footprint. Popularity is only supporting evidence, but it provides little reassurance about long-term maintenance capacity.
The linked repository is not archived, which is a meaningful counterweight to the old release history, although it was last pushed in November 2021.
The repository has no security policy or security scanning tooling, reducing transparency for a package that handles external service integrations. This is a hygiene and maintenance concern rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.