Risky to adopt: Packagist marks the package abandoned, and it has had no release or commit activity in the last 12 months. The repository is licensed, documented, and not archived, but those positives do not offset the package-level abandonment warning.
28%
Total Score
50
71
75
Packagist marks the package abandoned at package scope, with no distinct replacement identified beyond the same package name. This is a severe adoption risk because the registry is explicitly warning that this dependency should no longer be relied on.
The package has only two releases since March 2021, with no releases in the last 12 months and a median release interval of about 4.5 years. The sparse release history materially increases abandonment and maintenance risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the absence of recent releases. Although the repository was pushed recently for the assessed release, there is no evidence of ongoing maintenance afterward.
The repository uses Composer for builds, which fits this PHP package. No security scanning is configured, a modest hygiene gap, but it does not outweigh the package abandonment warning on its own.
The repository has no published security policy. This weakens vulnerability-reporting transparency, though the small package scope and other repository documentation provide limited compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0|~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.