The MIT license and direct repository match make the package transparent enough to inspect. Its small dependency surface is reasonable, but adoption carries maintenance risk; pin it only if you can own fixes.
38%
Total Score
25
100
69
83
The package has had 3 releases, but none in the last 12 months; the latest release was nearly four years ago. This is strong evidence of abandonment risk for a library dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and indicating no observed ongoing maintenance.
Only one registry maintainer is listed, and project_backing identifies a user-owned repository rather than an organization. That leaves limited visible maintenance capacity, especially alongside the lack of recent activity.
The artifact has no README, tests, or changelog; missing tests and changelog are normal for published artifacts, but a missing README is a real consumer-documentation gap for an SDK. The GitHub release flag is a small positive, although it has no release notes excerpt.
The repository has 0 stars and 0 forks, with 2 watchers. Popularity is only supporting evidence, but these low adoption signals provide no compensating evidence for the maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version >=6.0 | — | — |
illuminate/support Version >=5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.