The package has no declared or detected license, and the repository has no security policy. It does include tests and a usable README, but the project offers limited reassurance for long-term maintenance.
44%
Total Score
0
67
50
The latest release was published in May 2020, about six years before collection, and there were no releases in the last 12 months. Fifteen releases show some historical activity, but the long release gap materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, despite a last push in April 2023. This indicates current maintenance has effectively stopped.
Neither the package metadata nor the repository contains a recognized license or license file. That creates a real transparency and adoption concern for a dependency.
The repository has zero stars, zero watchers, and one fork. Popularity is only supporting evidence, but these low adoption signals provide little additional confidence in ongoing project support.
The repository has no security policy. This is a maintenance and disclosure gap, though it is less serious than the prolonged lack of releases and commits.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.