MIT licensing, a focused dependency set, and a matching README make the package easy to understand and integrate. There is no published security policy, so security contacts and handling expectations are unclear.
55%
Total Score
50
100
75
75
The package has only two releases, with the latest published nearly 8 years ago and no releases in the last 12 months. This is strong evidence of inactive maintenance, though the stable 1.0.1 release may be intentionally mature.
There were no commits and no active maintainers in the last 3 months, consistent with the nearly 8-year gap since the last push. This materially increases abandonment and compatibility risk.
Composer is used for builds, but no security-scanning tool was detected. For a small PHP library this is a transparency and maintenance-hygiene gap, not evidence of unsafe behavior by itself.
The linked repository is not archived, but its last push was nearly 8 years ago. The unarchived status preserves some continuity while not overcoming the age of the source.
The repository has no security policy. That leaves no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.