The package is small, licensed under MIT, and has a usable README with only two runtime dependencies. Its source has seen no commits for more than seven years, with no tests, security policy, or recent release activity, leaving maintenance risk high.
42%
Total Score
0
100
69
50
The latest release was published more than seven years ago, and there were no releases in the last 12 months. This is strong evidence of abandonment for a package that may need compatibility updates.
There were zero commits and zero active maintainers during the last three months, indicating no current maintenance capacity; combined with the old latest release, this materially increases abandonment risk.
The repository name does not match the package name and its README does not mention the package, so the repository may not clearly establish ownership of this published package.
The repository uses Composer, providing basic build and dependency tooling, but it has no security-scanning tools. This is a minor transparency and hygiene gap rather than a standalone adoption blocker.
The linked repository is not archived, so it remains administratively available. However, its last push was in February 2019, which is consistent with the maintenance concern shown by release history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.