The package has a clear MIT license, README, tests, and changelog. Its small dependency surface and no install scripts reduce maintenance and installation concerns.
40%
Total Score
25
100
78
75
Only three releases were published, all clustered in May 2023, with no releases in the last 12 months despite the package being over three years old. This is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, and its last push was in May 2023. The long absence of source activity materially lowers confidence in ongoing maintenance.
The package has one registry maintainer. Because the repository is owned by an individual rather than an organization, there is little visible redundancy if that maintainer stops publishing.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy package, but these numbers provide no supporting evidence of a broader maintenance or review community.
Composer is used for builds, but the repository reports no security-scanning tools. This is a hygiene gap that adds uncertainty to a package with no recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.