Licensing is documented, install scripts are absent, and the repository matches the package. The user-owned project has no security scanning or security policy, reducing confidence in ongoing maintenance and release oversight.
42%
Total Score
50
100
67
83
The package shows 881 releases but its latest recorded release is 2019-11-24, with no releases in the last 12 months; this strongly suggests the published line is no longer maintained.
Apache-2.0 is declared and license files are present, so the release is licensed; the artifact also detects MIT text not covered by the declaration, which creates a minor licensing-clarity concern.
Only Amazon Web Services has registry publishing access. That is not itself a maintenance verdict, but combined with the user-owned repository and long inactivity it provides little evidence of an active publishing team.
The linked repository is owned by a user account rather than an organization, so the project has weaker visible institutional backing to offset its prolonged inactivity.
There were no new issues, closed issues, pull requests, or merged pull requests in the last month, and there are no open pull requests to show active development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.4.1 | — | — |
guzzlehttp/guzzle Version ^5.3.3|^6.2.1 | — | — |
guzzlehttp/promises Version ~1.0 | — | — |
mtdowling/jmespath.php Version ~2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.