The repository is tiny, has one maintainer, and offers no security policy or scanning. The MIT license, matching repository, and working Composer metadata provide basic transparency.
42%
Total Score
25
100
63
75
The latest release was about 3 years and 1 month ago, with no releases in the last 12 months. This indicates strong abandonment risk despite six total releases.
There were no commits and no active maintainers in the last 3 months, consistent with a project that has been inactive for about 3 years. This materially raises maintenance risk.
Only one registry maintainer is listed, leaving little visible publishing redundancy. The repository is user-owned rather than organization-backed, so there is no provided evidence of broader support.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of community support.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a hygiene gap, not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.