It has a clear README, tests, an MIT declaration, and only one runtime dependency. Those strengths do not offset package deprecation and the absence of release or repository activity since 2016.
18%
Total Score
100
50
75
Packagist marks the entire package as abandoned, with no replacement provided. That is a severe adoption risk even though the release itself is stable.
The package has only two releases, with the latest published in October 2016 and none in the last 12 months. This indicates roughly nine years of release inactivity and high abandonment risk.
The repository is not formally archived, but it was last pushed in October 2016. That long period without repository activity provides little evidence of ongoing maintenance.
The repository has no security policy. For a small, inactive SDK this is a transparency gap, although the package's deprecation and inactivity are substantially more important concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.