The project has clear documentation, tests in the repository, regular releases, and organization backing. Recent work is limited to one contributor, with no security scanning and two unpinned workflow actions, so maintenance and build hygiene deserve attention.
68%
Total Score
70
100
94
67
post-install-cmd and post-update-cmd scripts add install-time behavior that developers should inspect, but this is a hygiene concern rather than a severe health risk by itself.
Only one account has registry publish access, which is a modest publishing resilience concern; organization backing provides some context but does not add another observed publisher.
All recent commits came from one contributor, creating concentration risk; organization ownership may allow handoff, but no second active contributor is observed.
Only 1 commit was recorded in the last 3 months, with 1 active maintainer, showing limited recent development activity despite the recent release cadence.
Composer build tooling is present, but no repository security scanning tools were detected, leaving a security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.