The package has a clear README, release notes, and no install-time scripts. Its small, matching repository and Composer build are transparent, but the long inactivity leaves maintenance and compatibility risk.
43%
Total Score
0
75
83
This package has only one release, published over four years ago, with no releases in the last 12 months. That is substantial evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the single-release history, this indicates no observable recent maintenance.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these counters provide little supporting evidence of active community use.
The repository uses Composer as its build tool, but it has no security-scanning tools. Composer support is appropriate; the missing scanning is a modest transparency gap rather than a severe risk.
The repository has no security policy. For a client library handling HTTP and reCAPTCHA-related functionality, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/recaptcha Version ^1.2 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.