The release and repository have seen no meaningful activity for about 12 years, leaving little evidence of ongoing maintenance. The MIT declaration is clear, but the package lacks a security policy and a consumer-facing README.
12%
Total Score
50
64
75
Packagist marks the entire package as abandoned and names guzzle/guzzle as its replacement, making continued adoption a severe maintenance risk.
The latest release was in August 2014, about 12 years ago, and there have been no releases in the last 12 months despite 40 historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive for about 12 years.
The published artifact has no README, which weakens consumer documentation for an HTTP library; the absence of tests and a changelog in the artifact is normal packaging practice.
The linked repository has no security policy, leaving vulnerability-reporting expectations undocumented; this adds a transparency gap to an already inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzle/common Version self.version | — | — |
guzzle/parser Version self.version | — | — |
guzzle/stream Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.