This is a young, pre-1.0 PHP library with good basic packaging and transparency: it has a clear README, an explicit BSD-3-Clause license, source tests, a small understandable file tree, no install-time lifecycle scripts, a matching organization-owned repository, and no deprecation or archive status. The main concerns are limited maturity—only two releases across 197 days—and no recorded commits or active maintainers in the last three months, alongside absent security scanning and security policy and unspecified GitHub Actions token permissions. It is reasonable to adopt with normal dependency pinning and review, but it does not yet have the maintenance track record of a mature dependency.
72%
Total Score
83
100
78
80
The package is only 197 days old with two releases and a median release interval of about 197 days, so its maintenance and release track record are limited.
There were zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance; the recent release push and young project age provide limited context but do not remove the concern.
The repository has only one star and no forks or watchers, providing little external adoption evidence; popularity is supporting evidence rather than a decisive health measure.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap for the repository.
No repository security policy was found, reducing disclosure and security-process transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.15.2 || ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.