The package includes a README, tests, an MIT license, and no install-time scripts. Its tiny project footprint and absent recent activity make long-term compatibility and support uncertain.
42%
Total Score
0
100
67
75
Only three releases were published, with none in the last eight years; the latest release was in July 2018. This is strong evidence of abandonment risk for a maintained dependency.
There were no commits and no active maintainers in the last three months, consistent with the roughly eight-year gap since the last release.
The repository name does not match the package name, and its README does not mention the package. That makes package ownership and source alignment less clear.
The repository has one star, one fork, and one watcher. Low popularity is only supporting evidence, but it indicates limited visible adoption or community support.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.