Tests, documentation, a clear MIT license, and a stable release make the package straightforward to evaluate. Its small release history and lack of security tooling or policy leave limited evidence for long-term maintenance.
65%
Total Score
50
100
83
90
The registry namespace and repository owner are user-owned rather than organization-owned, so there is no visible organizational backing to compensate for the thin maintenance evidence.
The package is only 161 days old with three releases, concentrated within about 9 hours, so there is limited evidence of sustained maintenance beyond its initial launch.
There were zero commits and zero active maintainers during the last three months, leaving a meaningful concern about ongoing maintenance.
The repository has zero stars, forks, and watchers. This is supporting evidence of limited adoption, but it is not decisive for a young, specialized client.
Composer is used for builds, but no security scanning tools are configured, leaving a security-hygiene gap without making the package unfit by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.