The small codebase has tests, a clear MIT license, and organization backing. Maintenance evidence is thin, with no recent commits, security policy, or automated security scanning.
60%
Total Score
83
100
88
75
The package has three releases, all concentrated within about six hours, and no release for roughly six months. That short, bursty history provides limited evidence of sustained maintenance.
There were no commits and no active maintainers during the last three months, while the repository was last pushed around six months ago. This is the strongest evidence of uncertain ongoing maintenance.
Composer is used for the build, which fits the package ecosystem. No security scanning tool is configured, leaving a modest repository-hygiene gap.
The repository has no security policy. That does not show a defect in the release, but it reduces transparency about how vulnerabilities would be reported and handled.
No GitHub Actions workflows were present to audit, so there are no workflow findings; this also provides no evidence of automated checks or release security controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.