It includes a README, tests, an MIT license, and only two runtime dependencies. Those strengths improve transparency and adoption, but they do not offset the lack of recent maintenance for a library dependency.
38%
Total Score
0
100
63
75
The package has had no release in about eight years, despite 15 total releases concentrated on June 5, 2018. Its stable 2.0.3 version is a modest positive, but the prolonged release gap signals abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the roughly eight-year pause in releases. No provided maintenance signal compensates for this lack of current activity.
Composer is used for the build, but no security-scanning tooling is present. That leaves a modest hygiene gap for a package that handles RPC connections.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a secondary concern compared with the maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.