Organizational backing, security scanning, tests, and release notes provide useful accountability. However, this dependency is deprecated and its source repository is archived, making long-term updates and support unreliable.
18%
Total Score
75
100
69
83
Packagist marks the entire package as abandoned with no replacement, directly indicating that new dependencies should not be built on it.
The linked repository is archived, despite being pushed recently; archived status is a severe sign that ongoing maintenance should not be expected.
The artifact contains an Apache-2.0 license file, so it is licensed; the manifest's Unlicense declaration conflicts with that detected license and reduces metadata clarity.
There were no commits and no active maintainers in the last 3 months, reinforcing the abandonment concern rather than compensating for it.
The single analyzed workflow scopes permissions read-only and has no reported audit findings, but both of its two action references are unpinned, leaving a modest reproducibility and update-integrity gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.