The repository is small but clearly tied to the package, with a readable guide, changelog, license, and stable release. Its very sparse release history and no recent commits make long-term maintenance uncertain; there is also no security policy or scanning.
62%
Total Score
50
100
88
75
The package and repository are owned by the same individual account, providing direct ownership alignment but no organizational backing or broader maintenance capacity.
The package has only two releases across about 5 years and none in the last 12 months, with a median interval of about 4.1 years. This is a meaningful maintenance concern, although the latest release was published in February 2025.
There were no commits and no active maintainers in the last three months. Combined with the sparse release history, this raises the risk that issues or compatibility work may not be addressed promptly.
The project uses Make and Composer for build tasks, which is a positive sign of basic project structure. No security scanning tooling is present, leaving a modest transparency and maintenance gap.
The repository has no security policy, so it does not document a process for reporting or handling vulnerabilities. This is a transparency weakness, though not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~7.2|~6.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.