The repository is small but has tests, a clear MIT license, and no install-time scripts. Its recent repository push does not offset nearly two years without a registry release and zero commits in the last three months.
58%
Total Score
50
100
78
83
The repository is owned by an individual account rather than an organization, so the single registry maintainer represents a relatively thin backing structure. The repository remains present and active enough to prevent this from being a severe concern.
The package has existed since 2016 with nine releases, but its latest registry release was nearly two years ago and there were no releases in the last 12 months. The repository's later push provides some evidence of activity but does not restore release cadence.
There were zero commits and zero active maintainers in the last three months. That is a concrete maintenance concern, even though the repository was pushed recently.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a small project but provides little evidence of an active user or contributor community.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked repository is the package's actual project source.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.