The source repository includes tests, a changelog, and a clear license, with no install-time scripts. Its single release and unchanged repository since June 2016 leave maintenance and compatibility risk too high for a new dependency.
28%
Total Score
75
100
67
75
Only one release exists, published in June 2016, with no releases in the last 12 months; this is strong evidence of abandonment risk.
The package omits a README, but that is a consumer-facing documentation gap; the repository does contain tests and a changelog, which provide useful project evidence.
There has been no recent issue or pull-request activity, consistent with a project that is no longer actively maintained.
The repository has zero stars and forks and only three watchers, offering no meaningful community signal to compensate for its age.
Composer is used for builds, but no security scanning tooling is present; this is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ~1.0 | — | — |
guzzlehttp/guzzle Version ~5.3|~6.0.1|~6.1 | — | — |
guzzlehttp/promises Version ~1.0 | — | — |
mtdowling/jmespath.php Version ~2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.