The package has a clear README, MIT declaration, and no install-time scripts. Its single release and zero recent commits leave maintenance and compatibility uncertain; the minimal four-file project also offers little evidence of ongoing engineering.
42%
Total Score
0
71
67
This package has made only one release, on January 3, 2024, with no releases in the following 12 months. That provides little evidence of sustained maintenance for a pre-1.0 client.
There were zero commits and zero active maintainers in the last three months, consistent with no repository changes since January 2024. This is strong evidence of abandonment risk.
The artifact and repository each contain only four files, including a README, manifest, and one source file. This compact structure may suit a small client, but it offers little visible evidence of testing or ongoing engineering.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are configured. The missing scanning is a hygiene gap, not evidence that the package is unsafe by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. For a client handling Zulip credentials, that weakens transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.