It has a clear MIT license, a matching repository, and a small, focused dependency set. The README and changelog help, but the single-maintainer project has no tests or security policy.
42%
Total Score
25
79
75
The package has only one release, published nearly eight years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a library dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the nearly eight-year release gap and providing no evidence of current maintenance.
One registry maintainer is a thin publishing base for a package with no recent release or commit activity, increasing continuity risk.
The repository has only 3 stars, 0 forks, and 2 watchers. Popularity is not decisive, but these low adoption indicators provide little supporting evidence of active stewardship.
The repository has no security policy, leaving vulnerability-reporting and response expectations unclear. This is a secondary transparency gap rather than evidence of an unsafe package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.