The long project history, stable release, tests, release notes, clear license, and small dependency set support adoption. The repository lacks a security policy, so security-response transparency is weaker than the otherwise solid package documentation.
68%
Total Score
50
100
92
75
The project has existed since August 2012 and has 15 releases, but only one release appeared in the last 12 months; this indicates a mature yet relatively infrequent maintenance cadence.
One contributor made 100% of the commits during the last three months, leaving maintenance dependent on a single active contributor.
Only one commit was recorded in the last three months, indicating limited recent development activity even though the repository was pushed recently.
The repository has no security policy, which weakens transparency about vulnerability reporting and response expectations.
All 11 analyzed action references are unpinned, so CI can change without a repository update; however, all three workflows were analyzed successfully and no dangerous triggers, injection paths, or audit findings were detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.