The package is clearly licensed, documented, and has a small, focused dependency set. Its very small community, no recent commits, and absent security policy leave maintenance and oversight concerns.
58%
Total Score
38
100
78
83
There were zero commits and zero active maintainers in the last three months, a strong sign that maintenance has stopped or is currently inactive.
One registry maintainer suggests limited publishing redundancy, although the repository is owned by the same individual, so this is a modest resilience concern rather than evidence of abandonment by itself.
The package and repository are consistently owned by the same individual account, providing clear ownership but no organizational backing or redundancy.
The package has only three releases and no releases in the last 12 months; the latest release was over four years ago, which indicates limited ongoing maintenance.
There are no open issues or pull requests and no recent activity; while this may mean the project is quiet rather than broken, it provides no evidence of active support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.