The small codebase is easy to inspect, with tests, a matching MIT license, and no install-time scripts. Its simple dependency profile and organization-backed repository help, but documentation and formal security oversight are limited.
42%
Total Score
50
100
75
83
This package has had only one release, with no releases in about 9 years, which is strong evidence of abandonment risk for a dependency.
There were no commits or active maintainers in the last 3 months, consistent with the long gap since the last repository update and indicating severe maintenance risk.
The package includes tests and a README, but the README is only 8 characters and offers little integration guidance; the absent changelog is normal packaging practice.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, reducing the visibility of how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.