Usable with caveats: the package is licensed, tested, documented, and not deprecated, but it has had no release or commit activity for over five years. Its small, single-maintainer project also lacks a security policy, so verify compatibility before adopting it.
58%
Total Score
38
100
78
90
The repository recorded zero commits and zero active maintainers in the last three months, consistent with more than five years without a release. This is the strongest evidence that ongoing maintenance should not be expected.
One registry maintainer is consistent with the repository being owned by the same individual, but it leaves little visible publishing redundancy if that maintainer stops responding. The long inactivity makes this thin maintainer base more relevant.
The registry namespace and repository are owned by the same individual, showing a consistent project identity. The user-owned project has no organizational backing shown, so continuity depends mainly on one maintainer.
The latest release was published over five years ago, with no releases in the last 12 months and only three releases overall. This indicates substantially reduced maintenance activity for a library dependency.
There are two open issues and one open pull request, but none were opened, closed, or merged in the last month. Unresolved work without recent response is a maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.1|^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.