This is a generally credible and usable release: it has a stable major version, a substantial release history since 2022, recent releases, a matching repository with extensive documentation and tests, a clear MIT license, no deprecation, no install-time scripts, and a low-risk read-only CI permission profile. The main concern is maintenance continuity: the repository recorded zero commits and zero active maintainers in the last 3 months despite a recent package release, while registry publishing is controlled by one person. The absence of a security policy and security-scanning tooling also leaves some transparency and assurance gaps. Overall, it is reasonable to depend on with ordinary monitoring, but its recent development activity warrants caution.
72%
Total Score
50
100
94
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.