It includes an Apache-2.0 license, tests, a README, and only two runtime dependencies. The repository has no security policy and no recent activity, so future fixes and compatibility updates are unlikely.
38%
Total Score
25
100
72
88
The latest release was about 5 years and 4 months ago, with no releases in the last 12 months. Although 42 releases show earlier activity, the long halt materially raises abandonment risk.
There were no commits and no active maintainers in the last 3 months, consistent with the multi-year release pause and indicating a strong likelihood of abandonment.
The repository is owned by an individual account rather than an organization, so the five registry maintainers do not demonstrate organizational backing or a broader maintenance team.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide no meaningful community-maintenance buffer.
Composer is used for builds, but no security-scanning tool is present. The missing scanning is a hygiene concern, not evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.