The README is present, the repository matches the package, and installation has no lifecycle scripts. Its maintenance appears dormant, while the license mismatch adds avoidable adoption uncertainty.
38%
Total Score
0
100
63
75
The package has only one release, published in January 2019, with no releases in the last 12 months. This strongly suggests the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long gap since its last release and indicating substantial abandonment risk.
The artifact contains a license file, but it is recognized as Apache-2.0 while the manifest declares MIT. The conflicting licensing information creates a real transparency concern.
The repository has 3 stars, 0 forks, and 2 watchers, providing little evidence of broad community support. Popularity is supporting evidence, so this reinforces but does not establish the maintenance concern.
Composer is used for builds, but no security-scanning tooling is present. This is a hygiene gap rather than a severe risk, especially given the package's small scope.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.