The package is small and clearly identified, with a README and no install-time scripts. Its single maintainer, inactive issue queue, and absent security policy leave ongoing support uncertain.
62%
Total Score
50
86
83
Only one registry publishing account is listed, leaving limited visible release capacity. The repository is user-owned rather than organization-backed, so there is no provided evidence of a broader publishing team.
The latest registry release was in August 2021, with no releases in the last 12 months and only three releases overall. This is a meaningful maintenance concern despite the repository having a recent push recorded.
There has been no new or closed issue or pull request activity in the last month, while one issue and one pull request remain open. This suggests limited recent project response.
Composer is used for the build, which fits the package, but no security scanning tools are reported. This is a modest security-process gap rather than a severe risk.
The linked repository has no security policy. That reduces transparency for reporting and handling security issues, although it does not by itself indicate unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.