The package includes tests, uses Composer, and declares MIT licensing. Its single-maintainer footprint and absent README reduce confidence for a library consumers must integrate.
44%
Total Score
33
100
78
75
There were zero commits and zero active maintainers in the last three months, with the last push nearly four years ago. This is the clearest maintenance and abandonment concern.
Only one registry maintainer is listed. That is a limited publishing base, and the repository's lack of recent activity provides no compensating evidence of an active team.
The artifact and repository contain tests, and this exact version has a GitHub release; the missing README and changelog are transparency gaps for a library, though the release itself is documented by its GitHub presence.
The repository owner is an individual user rather than an organization. This is not inherently unhealthy, but it offers no organizational backing to offset the narrow maintainer base.
Only three releases were published, all concentrated in October 2022, with no release in nearly four years and none in the last 12 months. This is strong evidence of stagnation for an API integration library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.