The MIT license and matching source repository provide basic transparency, while two contributors share recent commit activity. That evidence is outweighed by the package’s withdrawn registry status and archived repository, so do not add it as a new dependency.
18%
Total Score
100
25
50
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning that the package should not be adopted for new work.
This is the only release, published about 10 years and 9 months ago, with no releases in the last 12 months. The absence of a release track makes compatibility and maintenance uncertain.
The linked repository is archived, which normally means active maintenance has ended. Although it was pushed recently, the archived state remains a severe adoption risk.
The repository has no security policy. This is a modest transparency gap, though it is secondary to the package being abandoned and archived.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hampel/json Version ~2.0 | — | — |
nesbot/carbon Version ~1.0 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.