The package is small and focused, with a tested artifact, clear licensing, and no install-time scripts. Its single-maintainer project has had no commits or releases since June 2020, so compatibility with current Guzzle and PHP should be checked.
52%
Total Score
50
100
88
75
Only one registry maintainer is listed. The repository is also owned by that individual rather than an organization, so there is limited visible redundancy if that maintainer stops supporting the package.
Only three releases were published, with the latest in June 2020 and none in the last six years. The focused scope may explain the small history, but the long release gap raises maintenance and compatibility concerns.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with no maintenance since June 2020. This is the strongest abandonment concern in the available evidence.
Composer build tooling is present, but no security scanning tools were detected. For this small library that is a hygiene limitation rather than evidence that the release is unsafe.
The repository has no security policy. This limits transparency around vulnerability reporting, though the package's small scope and clear source reduce the severity of the gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.