The package has a long release history, regular monthly releases, clear documentation, and a release note for this version. Its organization backing helps, but recent work comes from one contributor and the workflow uses three unpinned actions without a security policy.
78%
Total Score
75
100
89
67
One contributor made all five commits in the last three months, creating a thin recent contributor base. Organization ownership provides some handoff capacity, but no second active contributor is shown.
There are three open issues and no recent issue or pull-request activity. This is a minor transparency and responsiveness concern, but it is outweighed by recent commits and releases.
The repository has one star, one fork, and one watcher. Low popularity is only supporting evidence and does not outweigh the demonstrated release cadence and organization backing.
Composer is used for builds, but no security-scanning tooling was detected. This is a modest process gap rather than evidence of unsafe code.
The repository has no security policy. For a cloud API SDK this reduces reporting transparency, though it is partly offset by the active organization-owned project and current releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.