Risky to adopt: the package has had no release or commit activity for over five years and remains at version 0.0.2. It also lacks licensing and a README, while the linked repository does not match the package name, making long-term support and provenance unclear.
32%
Total Score
0
100
50
100
Only three releases were published, all within about three days in August 2021, with no release in more than five years. This strongly indicates abandonment rather than an actively maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since August 2021.
Neither the registry metadata nor the artifact or repository contains a license. That creates a real legal and reuse barrier for a package intended as a dependency.
The artifact includes tests, which is a positive quality signal, but it has no README, leaving consumers without documented integration guidance. The missing changelog is not a concern because changelogs belong in the source project and are not required in published artifacts.
The linked repository name does not match the package name, and no README package mention was available to establish the relationship. This leaves the package-to-source linkage unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version 6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.