Usable with caveats: the package is correctly backed by a matching organization repository and has a stable MIT-licensed release, but it has not released anything since July 2023. Its very small public footprint and lack of a security policy make long-term maintenance less reassuring.
62%
Total Score
100
100
83
90
The package has 37 releases, but its latest release was in July 2023 and it has had no releases in the last 12 months. That long release gap is a meaningful maintenance concern, despite the earlier release history.
The repository has only 1 star, 0 forks, and 2 watchers. Popularity is not decisive for a small library, but this very limited adoption provides little supporting evidence of ongoing community scrutiny.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy. That weakens the project's documented process for handling vulnerabilities, especially alongside the multi-year release gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/guzzle Version ^3.0 || ^2.2 | — | — |
pimple/pimple Version ^3.5 | — | — |
symfony/cache Version ^6.0 || ^5.0 || ^4.3 || ^3.3 | — | — |
psr/simple-cache Version ^3.0 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.