The source contains only three files and no tests or changelog, limiting evidence for safe integration. Its MIT license and lack of install scripts are positive but do not offset the absence of maintenance.
8%
Total Score
25
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the release.
The package has seven releases, all concentrated in April 2016, with no release in roughly 10 years. This strongly indicates abandonment rather than an actively maintained stable project.
The linked repository is archived and was last pushed in April 2016, so ongoing maintenance and issue response should not be expected.
The artifact and repository are extremely small, containing only three and four files respectively. That may be appropriate for a minimal package, but it provides little implementation or maintenance evidence alongside the lack of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.