The package is small and clearly scoped, with a usable README and a stable v1.1 release. Its dependencies are limited, but the project offers little ongoing maintenance or security transparency.
40%
Total Score
50
100
72
88
The package has only two releases, both in June 2018, and no releases in roughly eight years. This is strong evidence of abandonment risk for a dependency that may need compatibility or security updates.
The package and repository are owned by an individual account rather than an organization. That is not inherently unhealthy, but it provides less visible institutional backing for a project with no recent activity.
There are no open issues or pull requests and no recent issue or pull-request activity. While no backlog is positive, the complete lack of recent activity reinforces the maintenance concern.
The repository has three stars and no forks or watchers, indicating limited external adoption and review. Popularity is supporting evidence, but this adds to the uncertainty around a long-unmaintained package.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest transparency gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.