The package has a clear README, MIT license, and release notes for this version. Its tiny project footprint and lack of security scanning add maintenance risk. Pin this version and plan for ownership if continued updates are important.
52%
Total Score
50
78
75
Only two releases exist, with no releases in the last 12 months; the latest was published in October 2023, indicating very low ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The repository has only 2 stars, 1 fork, and 1 watcher, so there is little visible community support or external review to compensate for the inactive maintenance profile.
Composer build tooling is present, but no security scanning tools are configured, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations unclear for a package handling cloud logging credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/guzzle Version ^2.0.0 | — | — |
psr/container Version ^1.0|^2.0 | — | — |
hyperf/contract Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.