The small package is clearly identified, licensed, and documented, with a simple dependency profile and no install-time scripts. Its limited project hygiene and single-person ownership add little support for long-term maintenance.
40%
Total Score
25
100
71
83
There has been only one release, published about 9 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a library that may need compatibility updates.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. The repository is not archived, but there is no observed recent maintenance.
One registry maintainer is consistent with a small user-owned project, but it leaves little visible redundancy if that person stops maintaining it.
Composer is used for the build, which supports reproducible package structure, but no security scanning tooling was detected. This is a modest hygiene gap rather than evidence of unsafe code.
The repository has no security policy. This is a transparency and issue-handling gap, although the package's small scope limits its weight compared with the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.