Risky to adopt: the latest release is nearly ten years old and the repository has had no recent commits or releases. It has a matching source repository, a README, and an MIT license, but maintenance appears effectively inactive.
38%
Total Score
25
100
67
83
The package has had only 4 releases, with the latest published on November 22, 2016, and none in the last 12 months. This is strong evidence of abandonment risk for a client library.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history and indicating inactive maintenance.
The registry namespace and repository owner are the same individual account, which supports ownership continuity but does not provide organizational backing against abandonment.
The repository has 0 stars, 1 fork, and 1 watcher, so there is little community evidence to offset the lack of current maintenance.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a modest transparency concern, while the build tooling is appropriate for this package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.