The README, release notes, and small dependency surface make the package easy to inspect, with no install scripts or workflow findings. Its one-person project has seen no release or issue activity since 2019 and provides no license, tests, or security policy, so pinning it carries substantial maintenance risk.
38%
Total Score
50
100
61
88
Neither the package nor the linked repository contains a declared or detected license or license file, leaving the legal terms for reuse unclear.
The package has had only two releases, both in July 2019, with no releases in the last 12 months; this indicates prolonged maintenance inactivity.
Only one registry account has publish access, consistent with the individually owned repository but leaving little visible publishing redundancy.
The package and repository are owned by the same individual account, confirming that the repository is plausibly connected but showing no organizational backing to compensate for the thin maintainer base.
There are no new or closed issues in the last month and one open pull request, consistent with a project that is not actively maintained.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.