Tests are present, and the release notes document a PHP 8 change. A single maintainer, no security policy or scanning, and completely unpinned workflow actions reduce transparency and maintenance confidence.
42%
Total Score
25
50
50
The package has only three releases and none in the last 12 months; its latest release was about five years and ten months ago. This strongly suggests abandonment risk despite the previously regular 48-day median interval.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of current maintenance.
One registry maintainer is a thin publishing base for a small package, increasing continuity risk when combined with the lack of recent release and commit activity.
Composer is used as the build tool, but no security scanning tool is present. That weakens routine dependency and code-risk visibility without making the package unfit by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency weakness, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.