The package has a readable README, a matching source repository, and a simple Composer-based artifact. Maintenance has effectively stopped, leaving compatibility and support risks for a modern project.
32%
Total Score
50
75
50
The latest release was in October 2018, with no releases in the last 12 months and only two releases overall. This is strong evidence that the package is no longer actively maintained.
The repository has had zero commits and zero active maintainers in the last three months, and was last pushed in October 2016. That reinforces the long-term maintenance gap.
The package contains only four files, including a README, manifest, and single source file, making it easy to inspect but offering little visible project depth for a client library.
Composer is used for builds, but no security scanning tooling is present. This is a minor transparency gap rather than evidence of abandonment on its own.
The source repository has no security policy. For an API client handling credentials and JWT authentication, that reduces transparency around vulnerability reporting.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.