The package is small, uses only three runtime dependencies, and has no install-time scripts. Its absent tests, security policy, and release documentation leave little evidence to offset the concerns; confirm licensing before adoption.
48%
Total Score
50
58
75
Neither the package nor the linked repository provides a declared or detected license file. This creates a genuine legal and transparency gap for adopters.
The artifact has no README, tests, or changelog, while the repository also reports no tests or changelog. The GitHub release mechanism is present, but no release notes were provided for this version.
The package has 23 releases over about 17 months, but only one release in the last 12 months; the release history is heavily clustered rather than consistently maintained.
The repository recorded zero commits and zero active maintainers over the last three months. Although a recent release exists, this provides weak evidence of ongoing maintenance.
The linked repository name does not match the package name, and the README mention could not be established. A monorepo mismatch can be normal, but this leaves package ownership less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.7 | — | — |
laravel/framework Version ^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.