The source repository has no recent commits or issue activity, and the package has not released in about 11 years. Licensing, repository tests, and a matching README provide useful transparency, but not enough to offset the apparent abandonment.
32%
Total Score
0
71
75
The package has only 2 releases, with the latest published about 11 years ago and none in the last 12 months. That is strong evidence of abandonment for a library expected to track a changing cloud platform.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and leaving no evidence of ongoing maintenance.
The repository has 1 star and 0 forks, offering little supporting evidence of adoption or an active community. Popularity is only supporting evidence, so this reinforces but does not determine the abandonment concern.
The repository is not marked archived, which is a modest positive, but its last push was about 11 years ago and therefore does not compensate for the lack of current activity.
No security policy was found in the repository. For a library handling cloud-service credentials, this is a meaningful transparency gap, though it is less severe than the maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~5.1 | — | — |
guzzlehttp/command Version 0.8.* | — | — |
mtdowling/transducers Version 0.3.* | — | — |
mtdowling/jmespath.php Version ~2.1 | — | — |
guzzlehttp/log-subscriber Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.