The package includes a clear README, tests, a matching repository, and no install-time scripts. Its MIT declaration and small dependency profile help, but the project offers too little ongoing maintenance evidence for a new dependency.
12%
Total Score
0
100
58
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because future fixes and support are not expected.
The repository had zero commits and zero active maintainers in the last three months. This confirms that current maintenance capacity is absent rather than merely undocumented.
The linked repository is archived, and its last push was in December 2024. An archived source project is a severe abandonment signal for a package intended as an API client.
The package has six releases since April 2022, but none in the last 12 months; its latest release was in December 2024. The long release gap weakens confidence in compatibility maintenance.
The repository has no security policy. This is a transparency gap, although the archived and deprecated status already carries the dominant adoption risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.