This is a generally healthy, actively published and maintained release: version 1.13.0 is stable, the package is not deprecated, releases continue regularly, the repository is not archived, and the project is backed by an organization. The package has clear documentation, an MIT license, reproducible Composer-based tooling, security scanning, and no analyzed dangerous workflow patterns. The main concerns are that recent repository activity is concentrated entirely in one contributor, the artifact omits tests and a changelog (although repository tests compensate for the former), and the repository lacks an explicit security policy and top-level workflow token permissions. These are meaningful hygiene and continuity concerns, but not enough to make the dependency broadly unsafe to adopt.
78%
Total Score
90
100
100
80
All 3 recent commits came from one active maintainer, creating a continuity risk. The organization-owned project provides some institutional mitigation, but no second recent contributor is shown.
The repository has no SECURITY.md or other detected security policy. This is a transparency and vulnerability-reporting gap, though it does not by itself indicate abandonment.
The one workflow lacks top-level token permissions, so its permissions are not explicitly constrained at the workflow level. No top-level write permissions were detected, making this a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.