It has a stable version and no install-time scripts, and the artifact includes tests and an MIT license. Its README describes Guzzle rather than this package, so documentation is unreliable.
38%
Total Score
25
67
83
The package has made no releases in roughly three years; its latest release was April 5, 2023, despite having only three releases overall. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
A single registry maintainer creates a thin publishing base and increases bus-factor risk for a small, user-owned project with no recent activity.
The artifact includes tests, a changelog, and a GitHub release, which support project maturity, but its README is clearly for Guzzle 3 rather than this package, weakening consumer transparency.
Composer is used for builds, which is appropriate for a Packagist package, but no security scanning tooling was detected, providing no compensating evidence for supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.