The package includes a clear README, Apache-2.0 licensing, and no install-time scripts. Its single-person ownership, negligible repository adoption, and absent security policy provide little ongoing support or oversight.
42%
Total Score
50
100
69
83
The package has had only one release, published over seven years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
One registry maintainer matches the repository's individual owner. That can be sufficient for a small package, but it leaves limited maintenance capacity when activity has stopped.
The repository has 0 stars, 1 fork, and 1 watcher. Popularity is only supporting evidence, but these counts provide no meaningful community or continuity signal.
The repository uses Composer for builds but has no security scanning tools. Composer is appropriate for this PHP package; the missing scanner is a minor hygiene gap rather than a decisive health issue.
The repository is not formally archived, but it was last pushed over seven years ago, which does not compensate for the lack of recent releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.