It has a current stable release, tests, a matching repository, and no install scripts or deprecation. Confirm which license applies before adoption; ongoing work is limited to one recent contributor and no security policy is present.
70%
Total Score
50
100
93
75
The manifest declares GPL-3.0-or-later, while the artifact license file is detected as LGPL-3.0. A license file exists and the repository also has one, but the mismatch requires clarification.
All recent commits came from one contributor, leaving maintenance dependent on a single individual. The repository is user-owned rather than organization-backed, so there is no shown handoff capacity to offset this concentration.
There was one commit in the last three months from one active maintainer, indicating some recent activity but limited ongoing development capacity.
The repository has no published security policy. This is a transparency and vulnerability-reporting gap, although it is not severe enough to make the release unfit by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.