Usable with caveats: the package is actively published by an organization and has a clear README, changelog, stable release, and matching source repository. Recent repository activity is very light and concentrated in one contributor, with no security policy or explicit workflow permissions.
68%
Total Score
67
88
67
The package is about 497 days old with seven releases and a latest release on July 15, 2026, but only one release occurred in the last 12 months, indicating a relatively slow cadence.
All recent activity comes from one contributor with 100% of commits, creating concentration risk. The organization-owned repository partly compensates because maintenance can be handed off internally.
Only one commit was recorded in the last three months, with one active maintainer, so current maintenance activity is limited.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.