The package has clear documentation, tests, changelog, and a matching Apache-2.0 license. However, it has had no release or repository commit activity for nearly five years, with no security policy and minimal adoption.
45%
Total Score
0
100
81
75
The latest release was nearly five years ago, and there were no releases in the last 12 months. This is strong evidence of stalled maintenance despite seven total releases.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long release gap and indicating no current maintenance capacity.
The repository has zero stars, one fork, and zero watchers. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a broader maintainer or user community.
The repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, although it is less serious than the absence of maintenance activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.5 || ~7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.