Risky to adopt: this stable library has had no release or repository activity for nearly six years. The missing README and absent security policy add transparency concerns, although it is not deprecated or archived and has a clear Apache-2.0 license.
40%
Total Score
50
67
75
The package has only one release, published nearly six years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a library dependency.
The repository has had zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
The published library has no README, which makes integration and usage harder for consumers; absent tests and changelog files are normal packaging practice and do not add concern here.
The repository has zero stars, forks, and watchers, providing no supporting evidence of community use or review. Popularity is only supporting evidence, so this reinforces rather than determines the maintenance concern.
The repository has no security policy, so there is no documented process for reporting vulnerabilities or handling security issues. This is a transparency gap, but not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~5.3.1||~6.0||~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.