The package includes usable documentation, a clear MIT license, and a focused dependency set. Its small user-owned project has limited adoption and lacks security-policy or scanning evidence.
55%
Total Score
67
100
83
75
The repository is owned by an individual user rather than an organization. Combined with the lack of recent commits, this provides limited visible maintenance backing.
The package has four releases over about one year, including two in the last 12 months, with releases initially arriving about four days apart. The latest release is about 10 months old, which adds some maintenance concern.
There were zero commits and zero active maintainers in the last three months. For a library dependency, that is evidence of currently inactive maintenance and raises abandonment risk.
The repository has one star, zero forks, and one watcher. This indicates very limited adoption and review, though popularity alone does not determine package health.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest repository hygiene gap, not evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.