Usable with caveats: the package is licensed, stable, not deprecated, and its repository is active enough to publish a recent release. However, there have been no commits in three months, there are no tests or changelog, and maintenance depends on one publisher.
62%
Total Score
50
100
78
90
Only one registry account has publishing access. That is a real continuity risk for a user-owned project, although the linked repository has matching ownership and a recent release.
A reasonably detailed README and documentation are present, but neither the package nor repository includes tests or a changelog, limiting verification and release transparency.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This supports ownership consistency while leaving the project dependent on a small backing base.
The package has existed for about 3 years and 9 months with 10 releases, including one in the last 12 months; this shows continuity, though the recent cadence is light.
The repository had zero commits and zero active maintainers in the last three months. Despite the recent release and non-archived status, this weakens evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.