Its small scope and clear README make the package easy to understand. The lack of recent development and testing leaves compatibility and maintenance risks for a long-term dependency.
40%
Total Score
33
100
64
83
The package has had only one release, published about 8 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last 3 months. Combined with the old last push, this indicates maintenance has effectively stopped.
The linked repository is owned by a user account rather than an organization, so there is no organizational backing signal to offset the thin maintenance evidence.
There are no open issues or pull requests and no recent activity. This is consistent with a dormant project, though it does not by itself show unresolved defects.
The repository uses Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.