The MIT license, included tests, and small dependency set support basic transparency. The project lacks a security policy and security scanning, leaving little evidence of ongoing review or response capacity.
38%
Total Score
50
100
72
83
The latest release was in April 2019, with no releases in the last 12 months despite a package age of about 7 years. This strongly raises abandonment risk, although seven historical releases show the package was once maintained.
There were no new or closed issues or pull requests in the last month. This supports the broader evidence of inactivity, though a zero issue count alone is not a severe concern.
The repository has zero stars, forks, and watchers, providing no supporting evidence of an active user or contributor community. Popularity is only supporting evidence, so this is a secondary concern.
Composer build tooling is present, but no security scanning tools were detected. The build setup is adequate for the package type, while the missing security checks reduce transparency around maintenance hygiene.
The repository is not archived, but it was last pushed in April 2019, consistent with the long release gap and indicating inactive source maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.