Documentation and licensing are in place, and installation has no lifecycle scripts. The release line has seen no registry release in 967 days, while recent work is handled by one contributor and the repository has no security scanning.
68%
Total Score
83
80
75
Only three releases exist, with none in the last 12 months; the latest registry release was 967 days ago. This is a meaningful maintenance concern, though recent repository commits provide partial compensation.
All 7 recent commits came from one contributor, leaving maintenance dependent on a single active person. Organization backing provides some handoff capacity but does not remove the concentration risk.
Composer is used for builds, but no security-scanning tools are configured. The missing scanning is a hygiene gap rather than evidence of unsafe behavior.
No repository security policy was found, reducing transparency for vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.