It has a clear MIT license, a README, tests, and a matching source repository. The small project footprint, absent security tooling, and long release gap make ongoing support uncertain.
61%
Total Score
75
81
50
The package has only 4 releases since October 2016, with no releases in the last 12 months and a median interval of about 700 days. The February 2025 release is not withdrawn, but the sparse cadence limits confidence in active maintenance.
There were 0 commits and 0 active maintainers in the last 3 months. Combined with no releases in the last 12 months, this is meaningful evidence of weak current maintenance.
The repository has 0 stars and 2 forks, indicating a very small public user base. Popularity is only supporting evidence, but this offers little external evidence of project maturity.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene concern rather than evidence that the package is unsafe.
The repository has no security policy. For a small API client this is a transparency gap, though the tested source tree and clear license provide some compensating evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version 6.5.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.