The repository is documented, licensed, and still has recent repository activity despite no recent package releases. Its small user-maintainer base, absent security scanning, and inactive issue and commit metrics leave maintenance continuity uncertain.
61%
Total Score
50
100
89
100
Registry publishing access is held by one person. Because the repository is user-owned rather than organization-backed, this leaves a relatively thin publishing and maintenance base.
The package has published 18 releases, but its latest registry release was on December 14, 2022, with no releases in the last 12 months. This is a meaningful freshness and maintenance concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push date is compensating evidence, but the measured commit activity still indicates uncertain ongoing development.
There are four open issues and two open pull requests, but no new or closed issues and no merged pull requests in the last month. This suggests limited recent project interaction.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a modest repository-hygiene gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.