It includes tests, a substantial README, and a source repository that matches the package. The one-person project has no security policy and little adoption evidence, leaving long-term support uncertain.
43%
Total Score
50
83
75
The registry lists one publishing account, but this is a user-owned project rather than organization-backed infrastructure. The small maintainer base adds some continuity risk alongside the inactive repository.
The package has only two releases, with the latest published in July 2021 and none in the last 12 months. That long period without releases is a meaningful maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's prolonged release inactivity. This raises abandonment risk.
The repository has just 1 star, 0 forks, and 2 watchers, providing little evidence of a broad user or contributor base to sustain maintenance.
The repository has no security policy. For an API client that handles access credentials, this is a transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.