The artifact is well structured, tested, documented, and clearly licensed, with a repository that matches the package. Its zero security tooling and very small community provide little additional assurance for future maintenance.
42%
Total Score
25
100
67
88
The package has had no releases in the past 12 months, and its latest release was about 10 years ago. This is strong evidence of abandonment risk, although the package is not deprecated or archived.
There were no commits and no active maintainers in the past three months. Combined with the last push being about 10 years ago, this is strong evidence that maintenance has stopped.
The repository is owned by a personal user account rather than an organization. This provides no visible organizational backing to offset the thin current maintenance evidence.
The repository has zero stars and three forks, offering little evidence of a broad active user community. Popularity is only supporting evidence, so this reinforces rather than determines the abandonment concern.
The repository uses Make and Composer, but no security scanning tools were detected. This is a meaningful hygiene gap, though it is less serious than the package's lack of current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/command Version 0.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.