The package is clearly documented, licensed, and easy to inspect. Its only release was in 2018, repository activity has stopped, and no tests or security scanning are visible, making long-term maintenance a concern.
44%
Total Score
33
100
72
90
There has been only one release, published in January 2018, with no releases in the last eight years. This is strong evidence of abandonment risk for a library dependency.
The repository had zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since 2018.
The package includes a substantial README with installation and usage examples, which supports adoption. The repository has no tests, leaving implementation quality less independently verified.
The registry namespace and repository are owned by the same individual account, providing direct ownership alignment but no organizational backing to broaden maintenance capacity.
There are no open issues or pull requests and no recent activity. While this may indicate a quiet project, it provides no evidence of current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.