The repository has had no commits in more than seven years and provides no security policy. MIT licensing, tests, release notes, and a matching repository add transparency but do not offset the project’s abandonment.
15%
Total Score
50
50
83
Packagist marks the entire package as abandoned, with no replacement supplied. This is a direct warning against taking a new dependency on it.
The package has 21 releases but none in the last 12 months; its latest release was in January 2019. Its earlier release history shows past activity, but not current maintenance.
There were no commits and no active maintainers in the past three months. Combined with the archived repository, this confirms that maintenance has stopped rather than merely slowed.
The linked repository is archived, and its last push was in January 2019. Archived source indicates the project is no longer maintained.
The project uses Composer, but no security scanning tools were detected. Composer supports standard builds; the missing scanning is a minor hygiene gap alongside the stronger maintenance concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
mtdowling/jmespath.php Version ^2.2 | — | — |
guzzlehttp/guzzle-services Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.