The package is easy to inspect, with eight files, one runtime dependency, and a matching repository. Its README is very short, and there is no security policy or license information. The release and commit history provide little evidence of ongoing maintenance.
55%
Total Score
50
100
75
88
No license declaration or license file was found in the package or repository, leaving the terms for reuse and distribution unclear.
One registry publishing account is listed. Because the repository is user-owned rather than organization-backed, this provides limited visible publishing redundancy.
The package and repository are tied to the same individual-owned project, with no organization backing shown; this limits visible continuity if that maintainer stops contributing.
There has been only one release, first published 503 days ago, with no releases in the last 12 months; this gives little evidence of sustained maintenance.
The repository had zero commits and zero active maintainers in the last three months, indicating no recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.