The package is clearly identified, MIT-licensed, and has a focused dependency set. Its registry and source have been inactive since April 2019, while the repository has little adoption and no security policy. Treat it as a legacy dependency.
45%
Total Score
0
100
81
83
The latest release was about 7 years ago, with no releases in the last 12 months. This strongly lowers confidence that defects or compatibility issues will be addressed.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and indicating likely abandonment.
The repository has 1 star, 0 forks, and 1 watcher, providing little evidence of a broad user or contributor community to compensate for inactive maintenance.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is secondary to the much stronger evidence of inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.