The package includes a clear README, a matching MIT license, and a small runtime dependency set. There is no repository security policy or automated security scanning, so ongoing maintenance and security practices are not well documented.
62%
Total Score
50
100
83
88
The repository is owned by an individual account rather than an organization, and the registry namespace differs from that owner. The README identifies the package in the repository, so there is no evidence it is piggy-backing on an unrelated project, but backing capacity appears limited.
The package is only 96 days old and has had two releases, with both released within about three days. This shows initial activity but provides little evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers during the last three months. For a package only 96 days old, this is an early warning that maintenance may have stopped after the initial release burst.
The repository has zero stars, forks, and watchers, providing no community adoption evidence. Popularity is only supporting evidence, so this modestly lowers confidence rather than determining the verdict.
Composer is used for the build, but no security scanning tools are configured. The build setup is appropriate, while the absent scanning reduces maintenance and security transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.