Usable with caveats: the package is licensed, stable, and backed by a matching repository, but it has had no release since December 2023 and no recent commit activity. Its very minimal README and absent security policy also limit transparency.
57%
Total Score
67
100
67
90
Only one registry account has publish access, which creates a narrow publishing base; the matching user-owned repository provides some backing but does not remove the single-maintainer continuity risk.
A README is present, but it contains only 12 characters and provides little guidance for a library integrating Tencent services. Missing tests and changelog files are not concerns for the published artifact, and repository test/changelog fields provide no positive evidence.
The package has seven releases, but the latest was published on December 13, 2023 and there were no releases in the last 12 months, indicating a long period without published maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, providing direct evidence that current development is inactive.
The repository name matches the package name, supporting identity, but the README does not mention the package, which weakens documentation and package-to-repository transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.