Risky to adopt: this release has not been updated since 2014, and the source repository has had no commits or active maintainers for about 8 years. It is not deprecated or archived and includes a usable README, but the long-standing inactivity makes abandonment and compatibility risks substantial.
38%
Total Score
38
100
78
90
The package has only two releases, both published in September 2014, with no release in about 12 years. This is strong evidence of abandonment for a library handling an external service.
The repository recorded zero commits and zero active maintainers over the last three months, despite being unarchived. Combined with the last push about 8 years ago, this is a major abandonment concern.
Only one registry account has publish access, leaving little visible publishing redundancy. This is a modest concern rather than decisive evidence because the linked repository is owned by the same individual.
The source repository is owned by an individual rather than an organization, so the single registry maintainer is not supported by visible organizational backing. The matching package reference in the repository provides some identity support.
There have been no new or closed issues and no pull requests merged in the last month, while two issues and two pull requests remain open. This indicates no recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fut/eahashor Version 1.0.0 | — | — |
fut/request-forge Version 2.0.* | — | — |
guzzlehttp/guzzle Version 4.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.